CVE-2026-4147: Stack memory disclosure in filemd5 command
Published Mar 17, 2026
·Updated
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.
Affected Software
9 affected components
MongoDB MongoDB Server
MongoDB MongoDB>=7.0.0<7.0.31
MongoDB MongoDB>=8.0.0<8.0.20
MongoDB MongoDB>=8.2.0<8.2.6
MongoDB MongoDB=8.3.0-alpha0
MongoDB MongoDB=8.3.0-alpha1
MongoDB MongoDB=8.3.0-alpha2
MongoDB MongoDB=8.3.0-alpha3
MongoDB MongoDB=8.3.0-rc1
Remediation
Patch Available
Event History
Mar 17, 2026
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-4147?
CVE-2026-4147 is classified as a medium severity vulnerability due to its potential for stack memory disclosure.
2
How do I fix CVE-2026-4147?
To fix CVE-2026-4147, upgrade to the latest version of MongoDB Server that addresses this vulnerability.
3
Who is affected by CVE-2026-4147?
Authenticated users with the read role in MongoDB Server are affected by CVE-2026-4147.
4
What type of information can be disclosed by CVE-2026-4147?
CVE-2026-4147 can lead to the disclosure of uninitialized stack memory, which may contain sensitive information.
5
Is there a workaround for CVE-2026-4147?
Currently, the best approach for CVE-2026-4147 is to apply the recommended patches or updates as they become available.