CVE-2026-4358: MongoDB
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.
Affected products
- MongoDB MongoDB: from 7.0.0, before 7.0.31 (fixed in 7.0.31); from 8.0.0, before 8.0.20 (fixed in 8.0.20); from 8.2.0, before 8.2.6 (fixed in 8.2.6)
Published 2026-03-17. Last modified 2026-06-17.