Security Advisory

CVE-2026-18706

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-11 18:34:37
Last updated 2026-08-11 20:27:45
Assigner mongodb
CVSS score 7.5
State PUBLISHED

Description

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.