CVE-2026-18709
EUVD-2026-5688311.08.2026, 19:17
An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency, cluster clock corruption, and violation of transaction atomicity guarantees.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.8 | CNA |
| mongodb | mongodb | 8.0 ≤ 𝑥 < 8.0.29 | CNA |
| mongodb | mongodb | 7.0 ≤ 𝑥 < 7.0.40 | CNA |
Common Weakness Enumeration