CVE-2026-4358: MongoDB

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.

Affected products

  • MongoDB MongoDB: from 7.0.0, before 7.0.31 (fixed in 7.0.31); from 8.0.0, before 8.0.20 (fixed in 8.0.20); from 8.2.0, before 8.2.6 (fixed in 8.2.6)

Published 2026-03-17. Last modified 2026-06-17.