An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-123633 |
|
History
Tue, 09 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths. | |
| Title | Metadata name collision on $-prefixed fields causes post-auth server crash | |
| Weaknesses | CWE-617 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-06-09T22:17:08.144Z
Reserved: 2026-05-27T17:48:04.380Z
Link: CVE-2026-9750
No data.
Status : Received
Published: 2026-06-09T23:17:04.510
Modified: 2026-06-09T23:17:04.510
Link: CVE-2026-9750
No data.
OpenCVE Enrichment
Updated: 2026-06-10T00:30:17Z
Weaknesses