CVE-2026-18693
EUVD-2026-5690911.08.2026, 19:17
An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert into the affected bucket could then result in the server accessing memory outside its intended bounds, potentially causing a server crash (denial of service), exposure of limited memory contents, or memory corruption.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mongodb | mongodb | 7.0.0 ≤ 𝑥 < 7.0.40 |
| mongodb | mongodb | 8.0.0 ≤ 𝑥 < 8.0.29 |
| mongodb | mongodb | 8.2.0 ≤ 𝑥 ≤ 8.2.12 |
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.8 |
| mongodb | mongodb | 9.0.0:alpha0 |
| mongodb | mongodb | 9.0.0:alpha1 |
| mongodb | mongodb | 9.1.0:alpha0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration