What is CVE-2026-18691?
This vulnerability in MongoDB Server's intra-cluster connection setup allows a network-adjacent attacker to influence the authentication mechanism between replica set members. This could lead to the exposure of the cluster's shared internal credential under certain conditions. Affected users should update MongoDB to the latest version and restrict network access.
Azərbaycanca: Bu boşluq MongoDB Server-in klasterdaxili əlaqə qurulmasında zəiflikdir. Şəbəkəyə çıxışı olan şəxs autentifikasiya mexanizmini manipulyasiya edərək klasterin daxili etimadnaməsini ifşa edə bilər. Sistem administratorları MongoDB-i ən son versiyaya yeniləməli və şəbəkə təhlükəsizlik tədbirlərini gücləndirməlidir.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: MongoDB
FAQ1
How does CVE-2026-18691 affect MongoDB?
This vulnerability in MongoDB Server's intra-cluster connection setup allows a network-adjacent attacker to influence the authentication mechanism between replica set members. This could lead to the exposure of the cluster's shared internal credential under certain conditions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.