CVE-2026-8063Disclosure(mongodb / mongodb)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When resolving a view, the server inspects the aggregation pipeline to determine whether it begins with an Atlas Search stage. For $rankFusion and $scoreFusion, this inspection reads the first element on each stage’s input pipeline array without first verifying that the array is non-empty. Supplying an empty pipeline causes a null pointer dereference and crashes the server. This issue affects MongoDB Server 8.2 versions prior to 8.2.7.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongodb

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-07); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
mongodb

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-07: 2Mentions · 2026-05-13: 1Mentions · 2026-06-24: 1Technical Details · 2026-05-07: 2Technical Details · 2026-06-24: 105-0705-1306-24
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-072
Disclosure2
2026-05-131
General1
2026-06-241
Disclosure1
Full discourse4 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🚨 CVE-2026-8063 MongoDB vuln: Authenticated users can crash mongod via $rankFusion or $scoreFusion with an empty pipeline on a view. Issue stems from improper aggregation pipeline inspection during view resolution. 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-8063 #MongoDB #CVE #CyberSecurity #Infosec #Vulnerability #ThreatIntel #SecurityResearch

    Post summary

    The post announces a newly disclosed crash vulnerability in MongoDB that affects authenticated users using specific aggregation pipeline operators with an empty pipeline on a view.

    0001074
    1.3K followersView on X
  • The NoSQL Nerd@NoSQLNerd
    Disclosure

    Warning, MongoDB: CVE-2026-8063 lets any authenticated user crash mongod via $rankFusion or $scoreFusion with an empty pipeline on a view. Root cause: improper aggregation pipeline inspection during view resolution. https://nvd.nist.gov/vuln/detail/CVE-2026-8063

    Post summary

    The post warns about a MongoDB vulnerability (CVE-2026-8063) that allows authenticated users to crash mongod when using specific empty aggregation pipelines; it explains the underlying cause but provides no exploitation code, patch, or evidence of active attacks.

    0000035
    14 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos MongoDB ❗ CVE-2026-8063 ❗ CVE-2026-6691 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-mongodb-2/ https://t.co/fBMnvP3jCv

    Post summary

    The tweet simply lists two MongoDB CVE identifiers, offering no additional technical details or actionables.

    0000099
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8063 An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When resolving a view, the server inspects the aggreg… https://www.cve.org/CVERecord?id=CVE-2026-8063

    Post summary

    The snippet provides a brief disclosure of a MongoDB vulnerability that allows an authenticated user to crash the mongod process by invoking $rankFusion or $scoreFusion with an empty pipeline on a view; no PoC, exploit, patch, or active exploitation details are mentioned.

    0000090
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbmongodb---

Explore more