A use-after-free security issue exists in the server's query execution memory tracking subsystem. An authenticated user with read privileges can trigger a write to freed heap memory through a sequence of standard database commands, leading to server process crash or potential memory corruption. No user interaction is required.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-130907 | Vendor Advisory Issue Tracking |
Configurations
History
16 Sep 2026, 20:36
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:* | |
| First Time |
Mongodb
Mongodb mongodb |
|
| References | () https://jira.mongodb.org/browse/SERVER-130907 - Vendor Advisory, Issue Tracking |
Information
Published : 2026-09-08 17:18
Updated : 2026-09-16 20:36
NVD link : CVE-2026-82061
Mitre link : CVE-2026-82061
CVE.ORG link : CVE-2026-82061
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-416
Use After Free
