PT-2026-40530 · Mongodb · Mongodb Server

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2026-8201

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt shared. Triggering this vulnerability requires control over the structure of a client's FLE-related query.
This issue impacts MongoDB Server’s mongocryptd component v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-8201

Affected Products

Mongodb Server