Out-of-Bounds Memory Write Vulnerability in MongoDB Server
CVE-2026-8053
8.7HIGH
What is CVE-2026-8053?
An issue in the MongoDB Server's implementation of time-series collections allows a user with write privileges to perform an out-of-bounds memory write within the mongod process. This vulnerability arises from inconsistencies in the internal mapping of field names to indices in the time-series bucket catalog. Under specific conditions, it may lead to arbitrary code execution, posing serious security threats for users of affected MongoDB Server versions.
Affected Version(s)
MongoDB Server 5.0 < 5.0.33
MongoDB Server 6.0 < 6.0.28
MongoDB Server 7.0 < 7.0.34
