Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-18691

MongoDB Server: intra-cluster authentication mechanism can be influenced, exposing the internal credential

Technology

MongoDB

CVSS Score

8.8 / 10.0

Affected Versions

8.3 before 8.3.8; 8.0 before 8.0.29; 7.0 before 7.0.40

Upstream Fix

8.3.8; 8.0.29; 7.0.40

Published

August 11, 2026

OSSeva Coverage

Fixed upstream

Description

A party with suitable network access can influence which authentication mechanism one replica set member uses when connecting to another. Under certain conditions the cluster's shared internal credential is then sent in a less-protected form and may be recovered, after which it could be used to authenticate as the internal superuser. Tracked as SERVER-130264. CVSS is MongoDB's CVSS 3.1 score as the CNA.

Upstream record: NVD · CVE.org

Is your MongoDB deployment affected?

If you're running 8.3 before 8.3.8; 8.0 before 8.0.29; 7.0 before 7.0.40, you need this patch. Book a discovery call to get covered.