CVE-2026-4148: ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators

Published Mar 17, 2026
·
Updated

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.

Affected Software

9 affected components
MongoDB MongoDB Server
MongoDB MongoDB>=7.0.0<7.0.31
MongoDB MongoDB>=8.0.0<8.0.20
MongoDB MongoDB>=8.2.0<8.2.6
MongoDB MongoDB=8.3.0-alpha0
MongoDB MongoDB=8.3.0-alpha1
MongoDB MongoDB=8.3.0-alpha2
MongoDB MongoDB=8.3.0-alpha3
MongoDB MongoDB=8.3.0-rc1

Event History

Mar 17, 2026
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-4148?

CVE-2026-4148 has been rated as high severity due to the potential for authenticated users to exploit the vulnerability.

2

How do I fix CVE-2026-4148?

To mitigate CVE-2026-4148, it is recommended to upgrade to the latest version of MongoDB Server that addresses this vulnerability.

3

Who is affected by CVE-2026-4148?

CVE-2026-4148 affects authenticated users with read role permissions in MongoDB's sharded clusters.

4

What is the impact of CVE-2026-4148?

The impact of CVE-2026-4148 includes potential system crashes or unauthorized memory access through crafted aggregation pipelines.

5

When was CVE-2026-4148 discovered?

CVE-2026-4148 was officially reported and documented in 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203