Security Advisory

CVE-2026-18697

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-11 18:39:03
Last updated 2026-08-11 20:29:08
Assigner mongodb
CVSS score 8.7
State PUBLISHED

Description

An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.