← back
CVE-2026-18699mediumCWE-476

Improper Input Validation in MongoDB Query Planner Leads to Denial of Service

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, affecting connected clients and in-flight operations.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
MongoDB · MongoDB Server