🔐 CVE Alert

CVE-2026-11933

HIGH 8.8

Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash.

CWE CWE-787
Vendor mongodb
Product mongodb
Ecosystems
Industries
Technology
Published Jun 12, 2026
Last Updated Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for mongodb mongodb

Be the first to know when new high vulnerabilities affecting mongodb mongodb are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

MongoDB / MongoDB
8.3.0 ≤ 8.3.3 8.2.0 ≤ 8.2.10 8.0.0 ≤ 8.0.25 7.0.0 ≤ 7.0.36 6.0 ≤ 6.0.28 5.0 ≤ 5.0.33 4.4.0 ≤ 4.4.30

References

NVD ↗ CVE.org ↗ EPSS Data ↗
jira.mongodb.org: https://jira.mongodb.org/browse/SERVER-128125