Medium severity6.6NVD Advisory· Published Aug 11, 2026· Updated Sep 16, 2026
CVE-2026-18706
CVE-2026-18706
Description
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- jira.mongodb.org/browse/SERVER-128551nvdVendor AdvisoryIssue Tracking
News mentions
1- MongoDB: 25 Vulnerabilities Disclosed, Including Critical BI Connector FlawsVypr Intelligence · Aug 12, 2026