What is CVE-2026-18699?
A vulnerability in MongoDB Server's query planner allows an authenticated user with read-level privileges to crash the server process by submitting a specially crafted query against a collection with a text index. This may lead to a denial of service, impacting connected clients. Users are advised to upgrade to the latest patched version.
Azərbaycanca: MongoDB Server-də sorğu planlaşdırıcısında aşkarlanmış bu boşluq, oxuma səviyyəli imtiyazlara malik autentifikasiya olunmuş istifadəçiyə xüsusi hazırlanmış sorğu ilə server prosesini dayandırmağa imkan verir. Bu, xidmət dayanmasına (Denial of Service) səbəb ola bilər. Təsirə məruz qalmamaq üçün MongoDB-ni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: MongoDB
FAQ2
What minimum access level is required to exploit CVE-2026-18699 to crash the MongoDB server?
To exploit this vulnerability, a user must be authenticated and have at least read-level privileges.
What measure should be taken to protect against CVE-2026-18699?
To protect against this vulnerability, it is recommended to upgrade MongoDB to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.