CVE-2026-9750: MongoDB

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.

Affected products

  • MongoDB MongoDB: from 7.0.0, before 7.0.35 (fixed in 7.0.35); from 8.0.0, before 8.0.24 (fixed in 8.0.24); from 8.2.0, before 8.2.10 (fixed in 8.2.10); from 8.3.0, before 8.3.3 (fixed in 8.3.3)

Published 2026-06-09. Last modified 2026-07-23.