216.73.217.22

CVE-2026-8053

· Published 13/05/2026 04:17 · Modified 13/05/2026 15:34

Labels: CVE-2026-8053 2026-05-13CVE-2026-8053CWE-787[email protected]

Essential information

Published
13/05/2026 04:17
Modified
13/05/2026 15:34
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions this can result in arbitrary code execution. This issue impacts MongoDB Server v5.0 versions prior to 5.0.33, v6.0 versions prior to 6.0.28, v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

NVD status

Status
Undergoing Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mongodb / mongodb server cpe:2.3:a:mongodb:mongodb_server:5.0:*:*:*:*:*:*:*
mongodb / mongodb server cpe:2.3:a:mongodb:mongodb_server:6.0:*:*:*:*:*:*:*
mongodb / mongodb server cpe:2.3:a:mongodb:mongodb_server:7.0:*:*:*:*:*:*:*
mongodb / mongodb server cpe:2.3:a:mongodb:mongodb_server:8.0:*:*:*:*:*:*:*
mongodb / mongodb server cpe:2.3:a:mongodb:mongodb_server:8.2:*:*:*:*:*:*:*
mongodb / mongodb server cpe:2.3:a:mongodb:mongodb_server:8.3:*:*:*:*:*:*:*

References