All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-18697
HIGHpublished 2026-08-11 19:17 UTC · 1 day ago · modified 2026-08-11 21:17 UTC
8.7
CVSS / 10
// description
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.
// weaknesses (CWE)
- CWE-617