CVE-2026-18703
EUVD-2026-5686111.08.2026, 19:17
An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms. This could allow authentication through a method the administrator intended to disable.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mongodb | mongodb | 8.2.0 ≤ 𝑥 ≤ 8.2.12 |
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.8 |
| mongodb | mongodb | 9.0.0:alpha0 |
| mongodb | mongodb | 9.0.0:alpha1 |
| mongodb | mongodb | 9.1.0:alpha0 |
𝑥
= Vulnerable software versions
Ubuntu Releases