Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-18691: MongoDB server intra-cluster connections may expose internal superuser password

CVE-2026-18691 · published 10 days ago
Summary

MongoDB server instances that communicate with each other inside a replica set can be tricked into sending the internal admin credential in a less‑secure way if an attacker can reach the network between the members. This could let the attacker recover the password and log in as the superuser on any node. Apply the latest MongoDB updates and limit network access to only trusted replica set members.

What to do
  • Update mongodb to version 8.3.8.
  • Update mongodb mongodb server to version 8.3.8 or later.
Affected software
Ecosystem VendorProductAffected versions
– mongodb mongodb server < 8.3.8
– mongodb mongodb >= 7.0.0, < 7.0.40
>= 8.0.0, < 8.0.29
>= 8.2.0, <= 8.2.12
>= 8.3.0, < 8.3.8
9.0.0
9.1.0
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Bitnami – mongodb >= 8.2.0, < 8.3.8
Fix: upgrade to 8.3.8
Original advisory text
Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to nodes in the deployment.
Severity
9.4 Critical
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-757Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
Timeline
Published17 Sep 2026
Updated27 Sep 2026
First seen11 Aug 2026
Sources
CVE-2026-18691 · MITRE
Track software like this
Free during beta