Description
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations could then result in a server crash or, potentially, execution of unintended code.
Published: 2026-08-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in MongoDB Server’s timeseries bucket lifecycle handling can let an authenticated user with write privileges trigger an internal reference to be used after its memory has been freed. This defect may cause the server to crash or, under certain conditions, execute unintended code, leading to both availability loss and a possible remote code execution vector.

Affected Systems

The vulnerability affects MongoDB Server. No specific version information is provided, so any deployment that runs the vulnerable timeseries bucket handling can be impacted.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity. The EPSS score is below 1%, suggesting that exploitation is unlikely at present. The flaw is not listed in the CISA KEV catalog. Exploitation would require an authenticated user with sufficient write rights; if achieved, the attacker could disrupt service or gain code execution capability.

Generated by OpenCVE AI on August 12, 2026 at 19:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to a version that fixes the timeseries bucket handling flaw.
  • Audit and restrict role‑based access control so that only trusted users possess write permissions on timeseries collections.
  • Monitor system metrics and logs for abnormal crashes or attempts to access freed memory, and set up alerts for sudden service interruptions.

Generated by OpenCVE AI on August 12, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations could then result in a server crash or, potentially, execution of unintended code.
Title Use-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code Execution
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-08-11T20:26:22.568Z

Reserved: 2026-08-03T15:53:26.067Z

Link: CVE-2026-18692

cve-icon Vulnrichment

Updated: 2026-08-11T20:26:17.603Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T19:17:23.317

Modified: 2026-08-28T21:16:15.740

Link: CVE-2026-18692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T20:00:04Z

Weaknesses