What is CVE-2026-18709?
This vulnerability allows an authenticated user with direct network access to a shard to improperly finalize a prepared transaction, bypassing coordination and leading to cross-shard data inconsistencies and cluster clock corruption. Upgrading MongoDB Server to the latest patched version is strongly recommended.
Azərbaycanca: Bu boşluq autentifikasiya olunmuş istifadəçiyə shard səviyyəsində hazırlanmış tranzaksiyanı yanlış şəkildə commit və ya abort etməyə imkan verir, bu da cross-shard data inconsistencies və cluster clock corruption ilə nəticələnə bilər. MongoDB serverini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: MongoDB
FAQ1
Does exploiting CVE-2026-18709 require the user to be authenticated?
Yes, this vulnerability allows an authenticated user to improperly finalize a prepared transaction on a shard, bypassing coordination.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.