
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18709 is an authorization bypass vulnerability in MongoDB Server that allows an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. It affects MongoDB Server versions 7.0.x before 7.0.40, 8.0.x before 8.0.29, and 8.3.x before 8.3.8. The vulnerability was published on August 11, 2026. It carries a CVSS v3.1 base score of 6.4 (Medium) and a CVSS v4.0 base score of 5.9 (Medium) (GitHub Advisory).
The root cause is classified as CWE-862 (Missing Authorization): MongoDB Server does not perform adequate authorization checks when an actor attempts to commit or abort a prepared transaction directly on a shard, bypassing the cluster's transaction coordinator (GitHub Advisory). The attack vector is adjacent network (the attacker must have direct network-level access to a shard), attack complexity is high, and the attacker must hold low-privileged credentials. Exploitation requires specific deployment conditions — namely, the presence of in-progress prepared transactions in a sharded cluster environment. The relevant upstream issue is tracked at MongoDB JIRA SERVER-130544.
Successful exploitation can result in cross-shard data inconsistency, cluster clock corruption, and violation of transaction atomicity guarantees within a MongoDB sharded cluster (GitHub Advisory). There is no confidentiality impact, but integrity and availability of the vulnerable system are both rated High, meaning an attacker could corrupt data state or disrupt cluster operations. The impact is confined to the vulnerable MongoDB cluster and does not propagate to subsequent systems.
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.141% (4th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment classifies exploitation as "none" with non-automatable attack characteristics.
MongoDB has released patched versions addressing this vulnerability: upgrade to MongoDB Server 7.0.40 or later (for the 7.0 branch), 8.0.29 or later (for the 8.0 branch), or 8.3.8 or later (for the 8.3 branch) (GitHub Advisory). As a workaround, implement network segmentation to restrict direct network access to MongoDB shards to only authorized administrative systems, and enforce strict authentication and authorization controls for transaction coordination operations. Monitor transaction logs for unauthorized commit or abort operations on prepared transactions.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."