Description
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions this can result in arbitrary code execution.

This issue impacts MongoDB Server v5.0 versions prior to 5.0.33, v6.0 versions prior to 6.0.28, v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
Published: 2026-05-12
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker who can write to a MongoDB database can trigger a time-series bucket catalog inconsistency that causes an out-of-bounds memory write. This flaw enables arbitrary code execution within the mongod process, potentially giving the attacker full control over the database server. The weakness is a classic memory-safety issue.

Affected Systems

MongoDB Server is affected. Versions prior to 5.0.33, 6.0.28, 7.0.34, 8.0.23, 8.2.9 and 8.3.2 are vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating high severity. No EPSS data is presently available, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with write privileges to the database, suggesting that the attack vector is limited to logged‑in users with sufficient permissions.

Generated by OpenCVE AI on May 13, 2026 at 01:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MongoDB Server to the lowest non‑vulnerable version (5.0.33 or newer, 6.0.28 or newer, 7.0.34 or newer, 8.0.23 or newer, 8.2.9 or newer, or 8.3.2 or newer).
  • Enforce least‑privilege on database users so that only trusted accounts have write access to time‑series collections.
  • Monitor database logs for anomalous write operations or other signs of exploitation attempts.

Generated by OpenCVE AI on May 13, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 18 May 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

Thu, 14 May 2026 05:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 May 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb
Mongodb mongodb Server

Wed, 13 May 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 13 May 2026 00:30:00 +0000

Type Values Removed Values Added
Description An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions this can result in arbitrary code execution. This issue impacts MongoDB Server v5.0 versions prior to 5.0.33, v6.0 versions prior to 6.0.28, v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
Title FlatBSON Duplicate Field Index Drift
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-05-14T03:56:09.398Z

Reserved: 2026-05-06T18:44:33.815Z

Link: CVE-2026-8053

cve-icon Vulnrichment

Updated: 2026-05-13T14:33:40.623Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-13T04:17:41.287

Modified: 2026-05-18T13:06:01.570

Link: CVE-2026-8053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T10:35:11Z

Weaknesses