THREAT OPS › Threat News › [NVD] CVE-2026-18687 (HIGH 7.1) — MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed reques
[NVD] CVE-2026-18687 (HIGH 7.1) — MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed reques
CVE-2026-18687 CVSS: 7.1 HIGH Published: 2026-08-11T19:17:22.467
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal w
Indicators of compromise
- CVE-2026-18687cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18687