Medium severity6.4NVD Advisory· Published Aug 11, 2026· Updated Sep 16, 2026
CVE-2026-18709
CVE-2026-18709
Description
An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency, cluster clock corruption, and violation of transaction atomicity guarantees.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- jira.mongodb.org/browse/SERVER-130544nvdVendor AdvisoryIssue Tracking
News mentions
1- MongoDB: 25 Vulnerabilities Disclosed, Including Critical BI Connector FlawsVypr Intelligence · Aug 12, 2026