NULL pointer dereference in MongoDB Server - CVE-2026-18699
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to null pointer dereference in MongoDB Server query planner when processing a specially formed query against a collection with a text index. A remote user can submit a specially formed query to cause a denial of service.
The server process may terminate unexpectedly, affecting connected clients and in-flight operations.