CVE-2026-18708

EUVD-2026-56915
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cycle. This could result in corruption of query results affecting other users and denial of service targeted at their operations on the same database. Impact is limited to the scripting engine's execution sandbox, which does not provide access to database, filesystem, or network resources.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 29.23%
Affected Products (NVD)
VendorProductVersion
mongodbmongodb
7.0.0 ≤
𝑥
< 7.0.40
mongodbmongodb
8.0.0 ≤
𝑥
< 8.0.29
mongodbmongodb
8.2.0 ≤
𝑥
≤ 8.2.12
mongodbmongodb
8.3.0 ≤
𝑥
< 8.3.8
mongodbmongodb
9.0.0:alpha0
mongodbmongodb
9.0.0:alpha1
mongodbmongodb
9.1.0:alpha0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mongodb
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
trusty
needs-triage
xenial
needs-triage