Integer underflow in MongoDB Server - CVE-2026-18687

 

Integer underflow in MongoDB Server - CVE-2026-18687

Published: August 18, 2026


Vulnerability identifier: #VU144130
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18687
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service and corrupt encrypted index data.

The vulnerability exists due to integer underflow in the Queryable Encryption maintenance operation when processing specially formed request parameters against the collection's encrypted field configuration. A remote user can submit a specially formed request to cause a denial of service and corrupt encrypted index data.

The issue can lead to excessive internal writes, resulting in resource exhaustion.


Affected software

MongoDB Server

How to mitigate CVE-2026-18687

Install security update from vendor's website.

MongoDB Server - addressed in versions 8.0.29, 8.3.8

External References

Related Security Bulletins