---
id: CVE-2026-18712
title: >-
  An issue in MongoDB Server's Queryable Encryption maintenance operations could
  allow an authenticated user with privileges on one encrypted collection to
  cause unauthorized modification or destruction of data belonging to a
  different col…
summary: >-
  An issue in MongoDB Server's Queryable Encryption maintenance operations could
  allow an authenticated user with privileges on one encrypted collection to
  cause unauthorized modification or destruction of data belonging to a
  different col…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-863
vendor: mongodb
product: mongodb
affected:
  - 'mongodb >= 7.0.0, < 7.0.40'
  - 'mongodb >= 8.0.0, < 8.0.29'
  - 'mongodb >= 8.2.0, <= 8.2.12'
  - 'mongodb >= 8.3.0, < 8.3.8'
  - mongodb = 9.0.0
  - mongodb = 9.1.0
patched:
  - mongodb 8.3.8
published: '2026-08-11'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T15:28:14.690'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18712'
references:
  - url: 'https://jira.mongodb.org/browse/SERVER-130633'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00179
epssPercentile: 0.0663
ingestedAt: '2026-08-29T19:41:16.334Z'
---

## Overview

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient validation of certain internal metadata references before they are used to perform operations on other namespaces.

## Affected

- `mongodb >= 7.0.0, < 7.0.40`
- `mongodb >= 8.0.0, < 8.0.29`
- `mongodb >= 8.2.0, <= 8.2.12`
- `mongodb >= 8.3.0, < 8.3.8`
- `mongodb = 9.0.0`
- `mongodb = 9.1.0`

## Remediation

Upgrade past the affected range:

- `mongodb 8.3.8`
