What is CVE-2026-18692?
An issue in MongoDB Server's handling of timeseries bucket lifecycle allows an authenticated user with write privileges to trigger a use-after-free condition. This can lead to a server crash or, potentially, execution of malicious code on the server.
Azərbaycanca: MongoDB Server-də "timeseries bucket lifecycle" idarəetməsində səhv aşkarlanıb. Bu, yazma hüququ olan autentifikasiya olunmuş istifadəçiyə artıq azad edilmiş yaddaşa istinad (use-after-free) yaratmağa imkan verir ki, bu da serverin çökməsinə və ya potensial kod icrasına səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: MongoDB
FAQ2
What privileges must an attacker have to exploit CVE-2026-18692 in MongoDB Server?
The attacker must be an authenticated user with write privileges.
What are the potential impacts of successfully exploiting CVE-2026-18692 on a MongoDB Server?
This vulnerability can lead to a server crash or, potentially, execution of malicious code on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.