CVE-2026-9746

MEDIUM

Server crashes in case of the use of exchange

Title source: cna
STIX 2.1

Description

When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special privileges needed. The user must be logged in to issue the statement.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 14.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-617
Status published
Products (4)
MongoDB/MongoDB Server 7.0.0 - 7.0.35
MongoDB/MongoDB Server 8.0.0 - 8.0.24
MongoDB/MongoDB Server 8.2.0 - 8.2.10
MongoDB/MongoDB Server 8.3.0 - 8.3.3
Published Jun 09, 2026
Tracked Since Jun 10, 2026