Algorithm Downgrade in MongoDB Server - CVE-2026-18691
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and authenticate as the internal superuser to nodes in the deployment.
The vulnerability exists due to selection of less-secure algorithm during negotiation in intra-cluster connection setup when one replica set member connects to another. A remote attacker can influence which authentication mechanism is used to disclose sensitive information and authenticate as the internal superuser to nodes in the deployment.
Exploitation requires suitable network access and occurs only under certain conditions where the cluster's shared internal credential is transmitted in a less-protected form and can be recovered.