Impact
A use‑after‑free flaw in the $graphLookup aggregation stage of MongoDB Server allows an authenticated user who can issue aggregation and memory‑management commands to trigger use of freed memory. Depending on the circumstances the attacker may cause the database process to crash, resulting in a denial of service, or may execute unintended code that could lead to remote code execution. The weakness is identified as CWE‑416.
Affected Systems
The affected product is MongoDB Server. All instances running versions prior to the fix that addressed the issue in issue SERVER‑128551 are vulnerable, regardless of deployment environment. The vulnerability is only exploitable when the attacker has legitimate credentials with permissions to perform aggregation queries and manage memory.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity. The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have authenticated access and sufficient privilege; once that condition is met, the flaw can be used to trigger a crash or potentially gain remote code execution, which would compromise the availability, confidentiality, and integrity of the affected database system.
OpenCVE Enrichment