Vulnerability Description
A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | >= 7.0.0, < 7.0.31 |
Related Weaknesses (CWE)
References
- https://jira.mongodb.org/browse/SERVER-118849ExploitVendor Advisory
FAQ
What is CVE-2026-4358?
CVE-2026-4358 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when a...
How severe is CVE-2026-4358?
CVE-2026-4358 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-4358?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongodb.