jira.mongodb.org
https://jira.mongodb.org/browse/SERVER-130247 CVE-2026-18711
HIGH
Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure
Record summary
CVE-2026-18711 has a selected CVSS score of 7.1 (high).
Description
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries against time-series collections. This could result in a server crash or disclosure of freed memory contents within query results.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MongoDB ServerBrowse MongoDB / MongoDB ServerDefault status: unaffected | CVE List | 8.3.0 to < 8.3.8 | affected |
| 8.0 to < 8.0.29 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-18711