THREAT OPS › Threat News › [NVD] CVE-2026-18708 (MEDIUM 6.4) — An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cycl
[NVD] CVE-2026-18708 (MEDIUM 6.4) — An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cycl
CVE-2026-18708 CVSS: 6.4 MEDIUM Published: 2026-08-11T19:17:25.670
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cycle. This could result in corruption of query results
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-18708cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18708