All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-18706
HIGHpublished 2026-08-11 19:17 UTC · 1 day ago · modified 2026-08-11 21:17 UTC
7.5
CVSS / 10
// description
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.
// weaknesses (CWE)
- CWE-416