Reachable assertion in MongoDB Server - CVE-2026-18707
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to reachable assertion in aggregation command handling when processing a specially formed aggregation command. A remote user can submit a specially formed aggregation command to cause a denial of service.
The issue can cause the server process to terminate unexpectedly.