What is CVE-2026-18707?
In MongoDB Server, an authenticated user, even one with no assigned privileges, can cause the server process to terminate unexpectedly by submitting a specially crafted aggregation command. This may result in a denial of service. Users are advised to update MongoDB to the latest patched version.
Azərbaycanca: MongoDB Server-də autentifikasiya olunmuş istifadəçi, o cümlədən heç bir imtiyazı olmayan şəxs, xüsusi hazırlanmış aggregation əmri göndərərək server prosesini gözlənilmədən sonlandıra bilər. Bu, xidmətin dayanmasına (Denial of Service) səbəb olur. Təsirə məruz qalmamaq üçün MongoDB-ni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: MongoDB
FAQ1
What command can an authenticated user with no privileges send to cause a Denial of Service in MongoDB Server?
An authenticated user, even one with no assigned privileges, can send a specially crafted aggregation command to cause the server process to terminate unexpectedly, resulting in a denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.