CVE-2026-18706: MongoDB

Medium severity, CVSS 6.6. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.

Affected products

  • MongoDB MongoDB: from 8.3.0, before 8.3.8 (fixed in 8.3.8); version 9.0.0 only

Published 2026-08-11. Last modified 2026-09-16.