CVE-2026-4148Disclosure(mongodb / mongodb)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mongodb mongodb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongodb

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 7 mentions (2026-03-17); latest day: 1
  • 9 total mentions across 3 days

Affected systems

Vendors
Products
mongodb

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 3d
02457Mentions · 2026-03-17: 7Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-17: 4Technical Details · 2026-03-18: 103-1703-1803-19
Signal classification3 categories
Disclosure
666.7%
General
222.2%
Patch
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-177
Disclosure5General1Patch1
2026-03-181
Disclosure1
2026-03-191
General1
Full discourse9 posts
  • dbugs@ptdbugs
    Disclosure

    ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators CVE: CVE-2026-4148 Vendor: Mongodb inc Product: MongoDB Server CVSS: 8.7 Credits: n/a Description: A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4148 • https://jira.mongodb.org/browse/SERVER-119319 #dbugs_vuln

    Post summary

    The post announces a use‑after‑free flaw in MongoDB’s aggregation engines, detailing the affected scenario and CVSS score, but provides no PoC, exploit details, or patch information.

    00011128
    633 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos MongoDB ❗ CVE-2026-4148 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-mongodb/ https://t.co/mNRfwYN4Oi

    Post summary

    A brief announcement cites CVE‑2026‑4148 affecting MongoDB and directs readers to external links for details, without providing further information about exploitation, patches, or technical specifics.

    0000193
    6.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4148 - High A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline. https://www.thehackerwire.com/vulnerability/CVE-2026-4148/ https://t.co/GbzGHWigzi

    Post summary

    CVE-2026-4148 is a use‑after‑free flaw in MongoDB sharded clusters that can be triggered by read‑role users via crafted aggregation pipelines; no PoC, exploit tool, patch, or active exploitation has been reported.

    0001059
    138 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4148 MongoDB Authenticated Use-After-Free Vulnerability in Aggregation Pipeline Operations https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4148

    Post summary

    The post lists CVE‑2026‑4148 with a generic title and a link, offering no concrete details or actionable information.

    0000159
    4.0K followersView on X
  • The NoSQL Nerd@NoSQLNerd
    Patch

    Security alert: severe vulnerability disclosed for MongoDB Server (CVE-2026-4148). Read the disclosure and apply patches or mitigations ASAP: https://vuldb.com/?id.351378

    Post summary

    An alert warns of the newly disclosed CVE-2026-4148 in MongoDB Server and urges users to apply available patches or mitigations promptly.

    0000019
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4148 A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup a… https://www.cve.org/CVERecord?id=CVE-2026-4148

    Post summary

    The text announces CVE‑2026‑4148 as a use‑after‑free flaw in MongoDB sharded clusters triggered by crafted aggregation stages, without evidence of exploitation, patches, or PoC.

    00000122
    56.7K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for MongoDB Server (CVE-2026-4148) https://vuldb.com/?id.351378

    Post summary

    A severe vulnerability (CVE‑2026‑4148) was disclosed for MongoDB Server; the provided VulDB link directs to further details.

    0000078
    2.1K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4148 - ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators Intel Report: https://ift.tt/grxaZKj

    Post summary

    A new MongoDB use‑after‑free vulnerability (CVE‑2026‑4148) affecting the classic engine’s $lookup and $graphLookup operators has been disclosed, with no patch, exploit, or claim of active exploitation mentioned.

    0000037
    336 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4148: HIGH] A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.#cve,CVE-2026-4148,#cybersecurity https://cvefind.com/CVE-2026-4148

    Post summary

    The text discloses CVE‑2026‑4148, a high‑severity use‑after‑free flaw in MongoDB sharded clusters that can be triggered by read‑role users via crafted aggregation pipelines.

    0000061
    602 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbmongodb---
Appmongodbmongodb8.3.0--
Appmongodbmongodb8.3.0--
Appmongodbmongodb8.3.0--
Appmongodbmongodb8.3.0--
Appmongodbmongodb8.3.0--

Explore more