PT-2026-40527 · Mongodb · Mongodb Server+1
CVE-2026-8053
·
Published
2026-05-05
·
Updated
2026-07-01
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MongoDB Server versions prior to 5.0.33
MongoDB Server versions prior to 6.0.28
MongoDB Server versions prior to 7.0.34
MongoDB Server versions prior to 8.0.23
MongoDB Server versions prior to 8.2.9
MongoDB Server versions prior to 8.3.2
Description
An issue in the time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the
mongod process. This occurs due to an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions, this memory corruption can lead to arbitrary code execution on the database server.Recommendations
Update to version 5.0.33 or later.
Update to version 6.0.28 or later.
Update to version 7.0.34 or later.
Update to version 8.0.23 or later.
Update to version 8.2.9 or later.
Update to version 8.3.2 or later.
Exploit
Fix
RCE
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongodb Server
Mongodb