Junglewise Threat Intelligence

CVE-2026-18709: MongoDB Server transaction coordination bypass in prepared transactions

CVE-2026-18709 · Severity: medium · CVSS 6.4 · Published 2026-08-11

Technologies: MongoDB Server. Vendors: MongoDB.

Executive brief

MongoDB Server is a popular database platform used to store and retrieve business-critical data in many organizations. An authenticated attacker with direct network access to a database shard can bypass the transaction coordinator and improperly commit or abort prepared transactions, leading to data inconsistency across database clusters and potential visibility of incomplete or torn data to other users.

Technical details

This vulnerability is a transaction coordination bypass affecting MongoDB's distributed transaction handling. An authenticated user can send commitTransaction or abortTransaction commands directly to a shard's primary, circumventing the intended transaction coordinator authorization checks. This allows attackers to manipulate cluster timestamps, cause torn reads, and create incomplete transaction results across shards. The attack is limited to the attacker's own transactions, but the resulting cross-shard data inconsistencies violate ACID transaction guarantees and can manifest as inconsistent data visible to all users. The fix enforces internal user authorization requirements for transaction commit/abort operations. Patches are available in MongoDB versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, and 9.1.0-rc0.

Affected products

  • MongoDB Server 7.0 before 7.0.40, 8.0 before 8.0.29, 8.2 before 8.2.13, 8.3 before 8.3.8, 9.0 before 9.0.0-rc2

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched

References