CVE-2026-4148: ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators
Published Mar 17, 2026
·Updated
A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.
Affected Software
9 affected components
MongoDB MongoDB Server
MongoDB MongoDB>=7.0.0<7.0.31
MongoDB MongoDB>=8.0.0<8.0.20
MongoDB MongoDB>=8.2.0<8.2.6
MongoDB MongoDB=8.3.0-alpha0
MongoDB MongoDB=8.3.0-alpha1
MongoDB MongoDB=8.3.0-alpha2
MongoDB MongoDB=8.3.0-alpha3
MongoDB MongoDB=8.3.0-rc1
Remediation
Patch Available
Event History
Mar 17, 2026
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-4148?
CVE-2026-4148 has been rated as high severity due to the potential for authenticated users to exploit the vulnerability.
2
How do I fix CVE-2026-4148?
To mitigate CVE-2026-4148, it is recommended to upgrade to the latest version of MongoDB Server that addresses this vulnerability.
3
Who is affected by CVE-2026-4148?
CVE-2026-4148 affects authenticated users with read role permissions in MongoDB's sharded clusters.
4
What is the impact of CVE-2026-4148?
The impact of CVE-2026-4148 includes potential system crashes or unauthorized memory access through crafted aggregation pipelines.
5
When was CVE-2026-4148 discovered?
CVE-2026-4148 was officially reported and documented in 2026.