Use-After-Free Vulnerability in MongoDB Server Products
CVE-2026-82061

7.2HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82061?

A use-after-free security vulnerability has been identified in the query execution memory tracking subsystem of MongoDB Server. This flaw can be exploited by an authenticated user with read privileges, allowing them to trigger a write operation to freed heap memory through a series of typical database commands. Such an exploit could lead to a crash of the server process or result in memory corruption, compromising the integrity and stability of the system. This issue highlights the importance of monitoring and patching database software to safeguard against potential exploitation.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.