216.73.217.80

CVE-2026-9750

· Published 09/06/2026 23:17 · Modified 10/06/2026 19:43

Labels: CVE-2026-9750 2026-06-09CVE-2026-9750CWE-617[email protected]

Essential information

Published
09/06/2026 23:17
Modified
10/06/2026 19:43
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mongodb / mongodb cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

References