What is CVE-2026-18711?
CVE-2026-18711 is a use-after-free vulnerability in MongoDB Server's query execution engine. An authenticated user with read and write privileges can cause an internal reference to be used after the underlying memory has been freed when running specific queries against time-series collections, potentially resulting in a server crash. Applying the security updates provided by MongoDB is recommended to mitigate this issue.
Azərbaycanca: CVE-2026-18711 MongoDB Server-in sorğu icra mühərrikində (query execution engine) istifadə olunmuş yaddaşın boşaldılmasından sonra istinad (use-after-free) zəifliyidir. Time-series kolleksiyalar üzərində müəyyən sorğular icra edərkən oxuma və yazma hüququ olan autentifikasiya olunmuş istifadəçi serverin çökməsinə səbəb ola bilər. Bu problemi aradan qaldırmaq üçün MongoDB tərəfindən təqdim olunan təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: MongoDB
FAQ2
What privileges must an attacker possess in order to exploit the CVE-2026-18711 vulnerability when running specific queries against MongoDB Server's time-series collections?
The attacker must be an authenticated user with both read and write privileges.
What impact on MongoDB Server's operation can result from the successful exploitation of the CVE-2026-18711 vulnerability?
Successful exploitation of this use-after-free vulnerability can potentially result in a server crash.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.