What is CVE-2026-18706?
A vulnerability in the $graphLookup aggregation stage of MongoDB Server could allow an authenticated user to reference freed memory, leading to a server crash or potential code execution. The issue is triggered by issuing aggregation and memory-management commands. Users are advised to update MongoDB to the latest stable version.
Azərbaycanca: MongoDB Server-in $graphLookup aqreqasiya mərhələsində istifadə olunmuş yaddaşın boşaldılmasından sonra daxili referansa müraciət etməyə imkan verən zəiflik aşkarlanıb. Bu, autentifikasiya olunmuş istifadəçinin aqreqasiya və yaddaş idarəetmə əmrlərini icra etməsi ilə serverin çökməsinə və ya potensial kod icrasına səbəb ola bilər. Təsirə məruz qalmamaq üçün MongoDB versiyasını ən son stabil versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: MongoDB
FAQ2
Which MongoDB component is affected by CVE-2026-18706?
The vulnerability affects the $graphLookup aggregation stage of MongoDB Server.
What action should be taken to mitigate CVE-2026-18706?
Users are advised to update MongoDB to the latest stable version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.