What is CVE-2026-18712?
A vulnerability in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to modify or destroy data in a different collection. This issue stems from insufficient validation of certain internal processes. Applying security patches provided by MongoDB is recommended to mitigate the risk.
Azərbaycanca: MongoDB Server-in Queryable Encryption funksiyasında autentifikasiya olunmuş istifadəçinin bir şifrələnmiş kolleksiyadakı imtiyazları ilə başqa kolleksiyaya aid məlumatları dəyişdirə və ya məhv edə biləcəyi zəiflik aşkarlanıb. Bu, müəyyən daxili proseslərdə kifayət qədər yoxlamanın olmaması səbəbindən baş verir. Təsirə məruz qalmamaq üçün MongoDB tərəfindən təqdim edilən təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: MongoDB
FAQ2
Which functionality in MongoDB Server is affected by CVE-2026-18712?
The vulnerability affects the maintenance operations of the Queryable Encryption feature.
What can an authenticated user do by exploiting CVE-2026-18712?
An authenticated user with privileges on one encrypted collection can modify or destroy data in a different collection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.