What is CVE-2026-18697?
CVE-2026-18697 is a vulnerability in MongoDB Server's aggregation framework. It allows an unauthenticated party to cause a 'mongos' (router) process to terminate unexpectedly by submitting a specially formed aggregation command, resulting in a denial of service (DoS) that disrupts client connections. Updating MongoDB is required to protect routed client connections.
Azərbaycanca: CVE-2026-18697 MongoDB Server-in aqreqasiya çərçivəsindəki boşluqdur. Bu, autentifikasiya olunmamış şəxsin xüsusi hazırlanmış aqreqasiya əmri göndərərək 'mongos' (router) prosesini gözlənilmədən dayandırmasına səbəb ola bilər ki, bu da xidmət imtinasına (DoS) yol açır. Təsirə məruz qalan router-lər vasitəsilə müştəri bağlantılarını qorumaq üçün MongoDB-ni yeniləmək lazımdır.
Related CVEs
link basis: shared vendor: MongoDB
FAQ2
Which component of MongoDB does CVE-2026-18697 affect?
This vulnerability affects the aggregation framework of MongoDB Server.
What happens upon successful exploitation of CVE-2026-18697?
An unauthenticated party can cause the 'mongos' (router) process to terminate unexpectedly by submitting a specially formed aggregation command, resulting in a denial of service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.