Description
A use-after-free security issue exists in the server's query execution memory tracking subsystem. An authenticated user with read privileges can trigger a write to freed heap memory through a sequence of standard database commands, leading to server process crash or potential memory corruption. No user interaction is required.
Published: 2026-09-08
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A use‑after‑free vulnerability exists in MongoDB Server's query execution memory tracking subsystem. An authenticated user with read privileges can send a sequence of standard database commands that trigger a write to freed heap memory, causing the server to crash or potentially corrupt memory. This flaw is a classic use‑after‑free (CWE‑416) and requires no user interaction beyond the database commands.

Affected Systems

MongoDB Server. Specific affected version information is not publicly disclosed in the advisory.

Risk and Exploitability

The CVSS score of 7.2 indicates moderate severity, and the EPSS score is not available. The vulnerability is not yet listed in CISA's KEV catalog. Exploitation requires an authenticated account with read permissions and the ability to execute custom database commands, which could be achieved by an internal user or a compromised account. Once triggered, the server process will crash, resulting in denial of service, and there is a potential for memory corruption that could affect other system components.

Generated by OpenCVE AI on September 8, 2026 at 18:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest MongoDB Server update that resolves the use‑after‑free issue
  • Restrict read‑only user privileges to the minimum required for legitimate operations and consider disabling them on critical collections until a patch is applied
  • Monitor database logs for anomalous command patterns and configure alerts for repeated failures or abnormal restarts of the server process

Generated by OpenCVE AI on September 8, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A use-after-free security issue exists in the server's query execution memory tracking subsystem. An authenticated user with read privileges can trigger a write to freed heap memory through a sequence of standard database commands, leading to server process crash or potential memory corruption. No user interaction is required.
Title Use-After-Free in MongoDB Server Query Execution Memory Tracking Subsystem Leads to Denial of Service
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:57:38.449Z

Reserved: 2026-08-27T22:51:58.545Z

Link: CVE-2026-82061

cve-icon Vulnrichment

Updated: 2026-09-08T17:57:25.918Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:34.837

Modified: 2026-09-16T20:36:31.050

Link: CVE-2026-82061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses