Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-18706

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 27.6%
CVSS Severity
CVSS v3 Score 6.6
Products affected by CVE-2026-18706


Contact Us

Shodan ® - All rights reserved