Junglewise Threat Intelligence

CVE-2026-18711: MongoDB Server use-after-free in query execution on time-series collections

CVE-2026-18711 · Severity: high · CVSS 7.1 · Published 2026-08-11

Technologies: MongoDB Server. Vendors: MongoDB.

Executive brief

MongoDB Server is a widely-used NoSQL database platform. An authenticated database user with read and write permissions can trigger a use-after-free memory vulnerability when executing specific queries against time-series collections. Exploitation can crash the database server or leak sensitive data from freed memory into query results, disrupting operations and potentially exposing confidential information.

Technical details

The vulnerability is a use-after-free flaw in MongoDB Server's query execution engine, specifically in how it handles Decimal128 values when preparing to yield or detach cursors on time-series collections. An authenticated attacker with read and write database privileges can craft queries that cause an internal reference to be used after the underlying memory has been freed. The attack vector is network-based and requires valid database credentials and appropriate permission levels. Successful exploitation can result in a server crash (denial of service) or disclosure of memory contents within query results. The issue has been fixed in versions 7.0.x (patched), 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, and 9.1.0-rc0.

Affected products

  • MongoDB Server 7.0, 8.0 (before 8.0.29), 8.2 (before 8.2.13), 8.3 (before 8.3.8), 9.0 (before 9.0.0-rc2), 9.1 (before 9.1.0-rc0)

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Fix versions released: 7.0.x, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2, 9.1.0-rc0

References