What is CVE-2026-18708?
This vulnerability in MongoDB Server's JavaScript scripting engine allows an authenticated user with write privileges to execute code in other users' query scope via a crafted stored value during an internal maintenance cycle. Immediate patching and strict review of user write permissions are advised to mitigate the risk.
Azərbaycanca: Bu zəiflik MongoDB Server-in JavaScript mühərrikindəndir və yazma səlahiyyətinə malik autentifikasiya olunmuş istifadəçiyə xüsusi hazırlanmış yadda saxlanılan dəyər vasitəsilə daxili baxım dövrü ərzində digər istifadəçilərin sorğu əhatəsində kod icra etdirməyə imkan verə bilər. Təsirə məruz qalan sistemlərdə dərhal rəsmi yeniləmə tətbiq edilməli və istifadəçi yazma icazələri ciddi şəkildə audit olunmalıdır.
Related CVEs
link basis: shared vendor: MongoDB
FAQ2
What level of access does an attacker need to exploit CVE-2026-18708?
The attacker must be an authenticated user with write privileges.
What measures are recommended to mitigate the risk of CVE-2026-18708?
Immediate patching and strict review of user write permissions are advised.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.