CVE-2026-9750 - Metadata name collision on $-prefixed fields causes post-auth server crash
CVE ID :CVE-2026-9750
Published : June 9, 2026, 10:17 p.m. | 48 minutes ago
Description :An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 9, 2026, 10:17 p.m. | 48 minutes ago
Description :An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...