CVE-2026-18706
EUVD-2026-5686311.08.2026, 19:17
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.8 |
| mongodb | mongodb | 9.0.0:alpha0 |
| mongodb | mongodb | 9.0.0:alpha1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration