← Back

CVE-2026-11933

nvd nist
Published: Jun 12, 2026Modified: Jun 22, 2026

JSON object

Loading...
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: CNA (Secondary)

Description

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash.

Affected (7)

Products: Mongodb: Mongodb
1 product
Mongodb
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Mongodb
From 4.4.0 to 4.4.31
From 5.0.0 to 5.0.34
From 6.0.0 to 6.0.29
From 7.0.0 to 7.0.37
From 8.0.0 to 8.0.26
From 8.2.0 to 8.2.11
From 8.3.0 to 8.3.4

References (1)

Source: cna@mongodb.com
PatchVendor Advisory

Timeline

No history available yet.