Denial-of-Service Vulnerability in MongoDB Server Products
CVE-2026-8336
7.7HIGH
What is CVE-2026-8336?
A vulnerability in MongoDB Server allows an authenticated user to trigger a denial-of-service condition. This occurs when the user executes certain internal JavaScript commands or utilizes the map function in a specific manner. When combined with features such as $where or $function, the server-side JavaScript engine may become unresponsive, leading to a crash of the backend services. This impacts various versions of MongoDB Server, necessitating prompt updates to mitigate potential exploitation.
Affected Version(s)
MongoDB Server 7.0 < 7.0.34
MongoDB Server 8.0 < 8.0.23
MongoDB Server 8.2 < 8.2.9
