CVE-2026-9747
Received
Received - Intake
MongoDB Server Crash via Aggregation Parameter Misconfiguration
Publication date: 2026-06-09
Last updated on: 2026-06-09
Assigner: MongoDB, Inc.
Description
Description
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-617 | The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary. |