Logo
vulnerabilityCVE-2026-9753
Name
CVE-2026-9753
Source
NVD ( link)Debian ( link)
Description
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
mongodb
Exploitable

Vulnerability Ratings#


7.2
CVSSv4
8.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
4.4.13
Exploitable
yocto
master
4.4.24
Exploitable