A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.
CVSS Details
- CVSS 4.0 Base Score: 6.1 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mongodb | — | Upgrade MongoDB to version 8.0.20Upgrade MongoDB to version 7.0.31Upgrade to the latest version of MongoDBUpgrade MongoDB to version 8.2.6 | Apr 27, 2026 | Mar 17, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.4.12Upgrade Splunk Enterprise to version 10.4.0Upgrade Splunk Enterprise to version 9.3.13Upgrade Splunk Enterprise to version 10.2.4Upgrade Splunk Enterprise to version 10.0.7 | Jul 30, 2026 | Mar 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub