Crafted cross-shard merge aggregation crashes MongoDB Server
CVE-2026-9747
7.1HIGH
What is CVE-2026-9747?
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.3
MongoDB Server 8.2.0 < 8.2.10
MongoDB Server 8.0.0 < 8.0.24