A vulnerability has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7 and classified as critical. This issue affects some unknown processing of the component Intra-cluster Connection Setup. This manipulation causes improper authentication.

This vulnerability is tracked as CVE-2026-18691. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.