CVE-2026-18712
MongoDB vulnerability analysis and mitigation

Overview

CVE-2026-18712 is an Incorrect Authorization vulnerability in MongoDB Server's Queryable Encryption feature that allows an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. The flaw stems from insufficient validation of certain internal metadata references before they are used to perform operations on other namespaces. Affected versions include MongoDB Server 7.0.x before 7.0.40, 8.0.x before 8.0.29, and 8.3.x before 8.3.8. It was published on August 11, 2026, with a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 7.2 (High) (GitHub Advisory, MongoDB Jira).

Technical details

The vulnerability is classified as CWE-863 (Incorrect Authorization), arising from MongoDB Server's Queryable Encryption maintenance operations failing to adequately validate internal metadata references before applying them to operations across different database namespaces. An authenticated attacker with low-level privileges on one encrypted collection can craft or manipulate maintenance operation requests such that the server incorrectly resolves metadata references to a different, unintended encrypted collection. No special configuration or user interaction is required beyond holding valid credentials with privileges on at least one encrypted collection (GitHub Advisory, MongoDB Jira).

Impact

Successful exploitation allows an authenticated attacker to cause unauthorized modification or destruction of data in encrypted collections they do not have explicit privileges over, resulting in high integrity and availability impact with no confidentiality exposure. This cross-collection data tampering could corrupt or permanently destroy sensitive encrypted data managed by other database users or applications, potentially causing significant data loss or service disruption. The scope is limited to the vulnerable MongoDB Server instance, with no evidence of subsequent system impact (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.175% (7th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authenticated access with at least low-level privileges on an encrypted collection, and the attack is not automatable according to NVD SSVC assessment.

Indicators of compromise

  • Logs: Unexpected audit log entries showing Queryable Encryption maintenance operations (e.g., compactStructuredEncryptionData) targeting collections that the executing user does not have explicit privileges on.
  • Logs: MongoDB server logs recording authorization decisions or namespace resolution errors during Queryable Encryption maintenance tasks across unrelated collections.
  • Database: Unexplained data modifications, deletions, or corruption in encrypted collections not associated with the authenticated user's assigned privileges.
  • Process: Unusual or repeated invocations of Queryable Encryption maintenance commands by database users who should not require them on multiple collections.

Mitigation and workarounds

MongoDB has released patched versions addressing this vulnerability: 7.0.40, 8.0.29, and 8.3.8. Users should upgrade to the appropriate fixed version as the primary remediation (GitHub Advisory, MongoDB Jira). As a workaround until patching is possible, restrict Queryable Encryption privileges strictly to only the collections that require them and enforce the principle of least privilege for all database user permissions. Additionally, monitor audit logs for unauthorized data modifications or deletions across collections to detect potential exploitation attempts.

Additional resources


SourceThis report was generated using AI

Related MongoDB vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18712HIGH7.2
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesAug 11, 2026
CVE-2026-18711HIGH7.1
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesAug 11, 2026
CVE-2026-18709MEDIUM5.9
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesAug 11, 2026
CVE-2026-18708MEDIUM5.3
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesAug 11, 2026
CVE-2026-18707MEDIUM5.3
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management