CVE-2026-18712 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Queryable Encryption improper authorization (Nessus ID 343460)
A vulnerability classified as problematic was found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. This issue affects some unknown processing of the component Queryable Encryption. The manipulation results in improper authorization.
This vulnerability was named CVE-2026-18712. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.