MongoDB Server vulnerability

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.

Published 11 Aug 2026Updated 16 Sep 20261 sources
CVSS 7.5

Source timeline

CVE record published by NVDView source ↗