CVE-2026-18693
- EPSS 0.23%
- Veröffentlicht 11.08.2026 18:38:31
- Zuletzt bearbeitet 16.09.2026 15:16:33
An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert into the affec...
CVE-2026-18705
- EPSS 0.27%
- Veröffentlicht 11.08.2026 18:37:54
- Zuletzt bearbeitet 16.09.2026 15:19:18
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling o...
CVE-2026-18704
- EPSS 0.21%
- Veröffentlicht 11.08.2026 18:37:23
- Zuletzt bearbeitet 16.09.2026 15:19:11
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being r...
CVE-2026-18692
- EPSS 0.41%
- Veröffentlicht 11.08.2026 18:36:54
- Zuletzt bearbeitet 16.09.2026 15:16:27
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations could then result...
CVE-2026-18688
- EPSS 0.27%
- Veröffentlicht 11.08.2026 18:36:21
- Zuletzt bearbeitet 16.09.2026 15:14:18
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server cras...
CVE-2026-18695
- EPSS 0.29%
- Veröffentlicht 11.08.2026 18:35:46
- Zuletzt bearbeitet 16.09.2026 15:17:17
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a denial of ser...
CVE-2026-18687
- EPSS 0.17%
- Veröffentlicht 11.08.2026 18:35:14
- Zuletzt bearbeitet 16.09.2026 15:14:07
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could su...
CVE-2026-18706
- EPSS 0.34%
- Veröffentlicht 11.08.2026 18:34:37
- Zuletzt bearbeitet 16.09.2026 15:19:25
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could re...
CVE-2026-18707
- EPSS 0.26%
- Veröffentlicht 11.08.2026 18:34:04
- Zuletzt bearbeitet 16.09.2026 15:19:32
An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of serv...
CVE-2026-18703
- EPSS 0.12%
- Veröffentlicht 11.08.2026 18:33:16
- Zuletzt bearbeitet 16.09.2026 15:19:02
An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authenti...