Integer underflow in MongoDB Server - CVE-2026-18687
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service and corrupt encrypted index data.
The vulnerability exists due to integer underflow in the Queryable Encryption maintenance operation when processing specially formed request parameters against the collection's encrypted field configuration. A remote user can submit a specially formed request to cause a denial of service and corrupt encrypted index data.
The issue can lead to excessive internal writes, resulting in resource exhaustion.