CVE-2026-4358Disclosure(mongodb / mongodb)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-415

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongodb

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
mongodb

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-17: 2Technical Details · 2026-03-17: 203-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4358 MongoDB Slot-Based Execution Engine Memory Corruption via Authenticated Aggregation Query https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4358

    Post summary

    The entry announces a new CVE, CVE‑2026‑4358, describing a memory‑corruption flaw in MongoDB triggered by authenticated aggregation queries, without providing any PoC, exploit, or remediation details.

    0000058
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4358 A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-bas… https://www.cve.org/CVERecord?id=CVE-2026-4358

    Post summary

    The text announces CVE‑2026‑4358, describing a memory corruption flaw triggered by an authenticated user with write privileges through a crafted $lookup aggregation query.

    0000068
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbmongodb---

Explore more