Algorithm Downgrade in MongoDB Server - CVE-2026-18691

 

Algorithm Downgrade in MongoDB Server - CVE-2026-18691

Published: August 18, 2026


Vulnerability identifier: #VU144144
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18691
CWE-ID: CWE-757
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and authenticate as the internal superuser to nodes in the deployment.

The vulnerability exists due to selection of less-secure algorithm during negotiation in intra-cluster connection setup when one replica set member connects to another. A remote attacker can influence which authentication mechanism is used to disclose sensitive information and authenticate as the internal superuser to nodes in the deployment.

Exploitation requires suitable network access and occurs only under certain conditions where the cluster's shared internal credential is transmitted in a less-protected form and can be recovered.


Affected software

MongoDB Server

How to mitigate CVE-2026-18691

Install security update from vendor's website.

MongoDB Server - addressed in versions 7.0.40, 8.0.29, 8.3.8

External References

Related Security Bulletins