PT-2026-48303 · Mongodb · Mongodb Server

Daffainfo

·

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2026-9753

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The $ internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $ internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-9753

Affected Products

Mongodb Server