Junglewise Threat Intelligence

CVE-2026-18697: MongoDB Server denial of service in aggregation framework

CVE-2026-18697 · Severity: high · CVSS 7.5 · Published 2026-08-11

Technologies: MongoDB Server. Vendors: MongoDB.

Executive brief

MongoDB Server's aggregation framework contains a flaw that allows an unauthenticated attacker to crash the mongos (router) process by sending a specially crafted aggregation command. This causes a denial of service that disrupts all client connections routed through the affected mongos instance, impacting application availability and user access to the database.

Technical details

The vulnerability exists in ExpressionFunction::parse(), which reads an internal-only _internalSetObjToThis flag from user-supplied BSON without verifying that the request originated from an internal client. An unauthenticated attacker can exploit this by sending a malformed aggregation command that forces stored-procedure loading, triggering an invariant failure that crashes the mongos process. The attack requires no authentication or special preconditions and is reachable over the network via the aggregation pipeline interface. The vulnerability has been patched in versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, and 9.1.0-rc0.

Affected products

  • MongoDB Server before 7.0.40, 8.0.x before 8.0.29, 8.1.x before 8.2.13, 8.3.x before 8.3.8, 9.0.x before 9.0.0-rc2, 9.1.x before 9.1.0-rc0

Timeline

  • 2026-08-11: disclosed: CVE-2026-18697 published
  • 2026-08-11: patched: Fixes released in versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, 9.1.0-rc0

References