← Back to CVE List
Vulnerability Intelligence Report
Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure

CVE-2026-18691

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to nodes in the deployment.

No Active Exploit Signals
CVSS Base Score
9.0
CRITICAL
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-757 ↗CWE-757: Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

Affected Products & Versions

Vendor Product Affected Versions
MongoDB MongoDB Server 8.3.0 < 8.3.8 (affected), 8.0 < 8.0.29 (affected), 7.0 < 7.0.40 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMongoDB, Inc. · Vendor · USA
Reserved2026-08-03T15:53:04
Published2026-08-11T18:46:02
Last Updated2026-08-11T20:22:00

LINK COPIED TO CLIPBOARD