Executive brief
MongoDB Server's aggregation pipeline operators ($percentile and $median) fail to properly validate user-supplied numeric parameters, allowing an authenticated attacker to crash the database server or potentially leak a small amount of memory. This affects the availability of database-dependent services and could expose sensitive information held in server memory.
Technical details
The vulnerability exists in the $percentile and $median aggregation operators' parameter validation logic in src/mongo/db/pipeline/accumulator_percentile.cpp. The validators use an ordered comparison (p < 0 || p > 1) to check that the percentile parameter p is in the valid range [0, 1]; however, IEEE-754 ordered comparisons against NaN always return false, allowing NaN values to bypass validation. When a NaN percentile is passed to the window-function rank-to-index conversion, it triggers an undefined-behavior float-to-int conversion, resulting in an out-of-bounds memory access. The fix changes validation to use a negated in-range test (!(p >= 0 && p <= 1)) that correctly rejects NaN, plus defensive integer conversion hardening. Authentication is required to invoke aggregation pipelines.
Affected products
- MongoDB Server Before 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, 9.1.0-rc0
Timeline
- 2026-08-11: disclosed: CVE-2026-18688 published
- 2026-08-11: patched: Fixes released in MongoDB 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, 9.1.0-rc0