CVE-2026-18709
MongoDB vulnerability analysis and mitigation

Overview

CVE-2026-18709 is an authorization bypass vulnerability in MongoDB Server that allows an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. It affects MongoDB Server versions 7.0.x before 7.0.40, 8.0.x before 8.0.29, and 8.3.x before 8.3.8. The vulnerability was published on August 11, 2026. It carries a CVSS v3.1 base score of 6.4 (Medium) and a CVSS v4.0 base score of 5.9 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): MongoDB Server does not perform adequate authorization checks when an actor attempts to commit or abort a prepared transaction directly on a shard, bypassing the cluster's transaction coordinator (GitHub Advisory). The attack vector is adjacent network (the attacker must have direct network-level access to a shard), attack complexity is high, and the attacker must hold low-privileged credentials. Exploitation requires specific deployment conditions — namely, the presence of in-progress prepared transactions in a sharded cluster environment. The relevant upstream issue is tracked at MongoDB JIRA SERVER-130544.

Impact

Successful exploitation can result in cross-shard data inconsistency, cluster clock corruption, and violation of transaction atomicity guarantees within a MongoDB sharded cluster (GitHub Advisory). There is no confidentiality impact, but integrity and availability of the vulnerable system are both rated High, meaning an attacker could corrupt data state or disrupt cluster operations. The impact is confined to the vulnerable MongoDB cluster and does not propagate to subsequent systems.

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.141% (4th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment classifies exploitation as "none" with non-automatable attack characteristics.

Mitigation and workarounds

MongoDB has released patched versions addressing this vulnerability: upgrade to MongoDB Server 7.0.40 or later (for the 7.0 branch), 8.0.29 or later (for the 8.0 branch), or 8.3.8 or later (for the 8.3 branch) (GitHub Advisory). As a workaround, implement network segmentation to restrict direct network access to MongoDB shards to only authorized administrative systems, and enforce strict authentication and authorization controls for transaction coordination operations. Monitor transaction logs for unauthorized commit or abort operations on prepared transactions.

Additional resources


SourceThis report was generated using AI

Related MongoDB vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18712HIGH7.2
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesAug 11, 2026
CVE-2026-18711HIGH7.1
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesAug 11, 2026
CVE-2026-18709MEDIUM5.9
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesAug 11, 2026
CVE-2026-18708MEDIUM5.3
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesAug 11, 2026
CVE-2026-18707MEDIUM5.3
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management