High severity7.5NVD Advisory· Published Aug 11, 2026· Updated Sep 16, 2026
CVE-2026-18697
CVE-2026-18697
Description
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- jira.mongodb.org/browse/SERVER-130110nvdVendor AdvisoryIssue Tracking
News mentions
2- MongoDB: 25 Vulnerabilities Disclosed, Including Critical BI Connector FlawsVypr Intelligence · Aug 12, 2026
- MongoDB Server: Thirteen Vulnerabilities Disclosed in Single BatchVypr Intelligence · Aug 11, 2026