CVE-2026-18687
EUVD-2026-5686411.08.2026, 19:17
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.8 | CNA |
| mongodb | mongodb | 8.0 ≤ 𝑥 < 8.0.29 | CNA |
Common Weakness Enumeration