CVE-2026-18701: MongoDB

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of service.

Affected products

  • MongoDB MongoDB: from 7.0.0, before 7.0.40 (fixed in 7.0.40); from 8.0.0, before 8.0.29 (fixed in 8.0.29); from 8.2.0, up to and including 8.2.12; from 8.3.0, before 8.3.8 (fixed in 8.3.8); version 9.0.0 only; version 9.1.0 only

Published 2026-08-11. Last modified 2026-09-16.