CVE-2026-18691
MongoDB Server: intra-cluster authentication mechanism can be influenced, exposing the internal credential
Technology
MongoDB
CVSS Score
8.8 / 10.0
Affected Versions
8.3 before 8.3.8; 8.0 before 8.0.29; 7.0 before 7.0.40
Upstream Fix
8.3.8; 8.0.29; 7.0.40
Published
August 11, 2026
OSSeva Coverage
Fixed upstream
Description
A party with suitable network access can influence which authentication mechanism one replica set member uses when connecting to another. Under certain conditions the cluster's shared internal credential is then sent in a less-protected form and may be recovered, after which it could be used to authenticate as the internal superuser. Tracked as SERVER-130264. CVSS is MongoDB's CVSS 3.1 score as the CNA.
Is your MongoDB deployment affected?
If you're running 8.3 before 8.3.8; 8.0 before 8.0.29; 7.0 before 7.0.40, you need this patch. Book a discovery call to get covered.