An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be… (CVE-2026-18708)
A vulnerability in MongoDB Server's JavaScript scripting engine allows an authenticated user with write privileges to execute code they control within the query scope of other users. This can lead to corruption of query results and denial of service for other users on the same database. The impact is confined to the scripting engine's sandbox and does not extend to database, filesystem, or network resources.
AI Analysis
Technical Summary
CVE-2026-18708 describes a vulnerability in MongoDB Server's JavaScript scripting engine where an authenticated user with write privileges can cause execution of attacker-controlled code within the query scope of other users. This occurs through a specially crafted stored value processed during an internal maintenance cycle. The vulnerability can corrupt query results and cause denial of service affecting other users' operations on the same database. The execution is limited to the scripting engine sandbox, preventing access to database contents, filesystem, or network resources.
Potential Impact
The vulnerability allows integrity and availability impacts limited to the scripting engine sandbox. Specifically, it can corrupt query results seen by other users and cause denial of service on their database operations. There is no confidentiality impact as the sandbox restricts access to database, filesystem, or network resources.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor communications for updates. In the meantime, limit write privileges to trusted users to reduce risk.
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be… (CVE-2026-18708)
Description
A vulnerability in MongoDB Server's JavaScript scripting engine allows an authenticated user with write privileges to execute code they control within the query scope of other users. This can lead to corruption of query results and denial of service for other users on the same database. The impact is confined to the scripting engine's sandbox and does not extend to database, filesystem, or network resources.
CVSS v3.1
Score 6.4medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18708 describes a vulnerability in MongoDB Server's JavaScript scripting engine where an authenticated user with write privileges can cause execution of attacker-controlled code within the query scope of other users. This occurs through a specially crafted stored value processed during an internal maintenance cycle. The vulnerability can corrupt query results and cause denial of service affecting other users' operations on the same database. The execution is limited to the scripting engine sandbox, preventing access to database contents, filesystem, or network resources.
Potential Impact
The vulnerability allows integrity and availability impacts limited to the scripting engine sandbox. Specifically, it can corrupt query results seen by other users and cause denial of service on their database operations. There is no confidentiality impact as the sandbox restricts access to database, filesystem, or network resources.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor communications for updates. In the meantime, limit write privileges to trusted users to reduce risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6xq3-wv9f-p92j
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-18708"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7c9b71bf8831d539ce0559
Added to database: 08/12/2026, 16:12:33 UTC
Last enriched: 08/12/2026, 17:26:24 UTC
Last updated: 08/13/2026, 02:41:00 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.