CVE-2026-8053 Details
Description
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions this can result in arbitrary code execution. This issue impacts MongoDB Server v5.0 versions prior to 5.0.33, v6.0 versions prior to 6.0.28, v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
A vulnerability in MongoDB Server's time-series collection feature allows an authenticated user with write privileges to cause an out-of-bounds memory write in the mongod process. This issue arises from a mismatch in the internal mapping of field names to indexes within the time-series bucket catalog, which under certain conditions can lead to arbitrary code execution. The vulnerability affects MongoDB Server versions 5.0.0 through 5.0.32, 6.0.0 through 6.0.27, 7.0.0 through 7.0.33, 8.0.0 through 8.0.22, 8.2.0 through 8.2.8, and 8.3.0 through 8.3.1.
Users are advised to upgrade to MongoDB versions 8.3.2, 8.2.9, 8.0.23, 7.0.34, 6.0.28, or 5.0.33.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jira.mongodb.org/browse/SERVER-126021 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mongodb mongodb | >= 5.0.0, < 5.0.33 >= 6.0.0, < 6.0.28 >= 7.0.0, < 7.0.34 >= 8.0.0, < 8.0.23 >= 8.2.0, < 8.2.9 >= 8.3.0, < 8.3.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | Initial Analysis | [email protected] |
| May 13, 2026 | New CVE Received | [email protected] |