Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-8053

MongoDB Server: out-of-bounds write in time-series collections with duplicate field names

Technology

MongoDB

CVSS Score

8.8 / 10.0

Affected Versions

8.3 before 8.3.2; 8.2 before 8.2.9; 8.0 before 8.0.23; 7.0 before 7.0.34; 6.0 before 6.0.28; 5.0 before 5.0.33

Upstream Fix

8.3.2; 8.2.9; 8.0.23; 7.0.34; 6.0.28; 5.0.33

Published

May 13, 2026

OSSeva Coverage

Fixed upstream

Description

An inconsistency in the field-name-to-index mapping of the time-series bucket catalog lets an authenticated user with database write privileges trigger an out-of-bounds memory write in mongod, which under certain conditions can lead to arbitrary code execution. Tracked as SERVER-126021. CVSS is MongoDB's CVSS 3.1 score as the CNA.

Upstream record: NVD · CVE.org

Is your MongoDB deployment affected?

If you're running 8.3 before 8.3.2; 8.2 before 8.2.9; 8.0 before 8.0.23; 7.0 before 7.0.34; 6.0 before 6.0.28; 5.0 before 5.0.33, you need this patch. Book a discovery call to get covered.