Beveiligingsadvies

CVE-2026-9753

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-09 22:30:57
Laatst bijgewerkt 2026-06-10 18:54:01
Toegewezen door mongodb
CVSS-score 8.1
Status PUBLISHED

Beschrijving

The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.