CVE-2026-9750
EUVD-2026-3586609.06.2026, 23:17
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mongodb | mongodb | 7.0.0 ≤ 𝑥 < 7.0.35 |
| mongodb | mongodb | 8.0.0 ≤ 𝑥 < 8.0.24 |
| mongodb | mongodb | 8.2.0 ≤ 𝑥 < 8.2.10 |
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration