CVE-2026-8063: Post-auth null pointer dereference when aggregating against a view with empty search pipeline

Published May 7, 2026
·
Updated

An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view.

When resolving a view, the server inspects the aggregation pipeline to determine whether it begins with an Atlas Search stage. For $rankFusion and $scoreFusion, this inspection reads the first element on each stage’s input pipeline array without first verifying that the array is non-empty. Supplying an empty pipeline causes a null pointer dereference and crashes the server.

This issue affects MongoDB Server 8.2 versions prior to 8.2.7.

Affected Software

2 affected components
MongoDB MongoDB Server<8.2.7
MongoDB MongoDB>=8.2.0<8.2.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MongoDB Server to a version that resolves this vulnerability.

    Fixed in 8.2.7
  2. Compensating control

    Avoid running $rankFusion or $scoreFusion with an empty pipeline on a view; ensure the pipeline is non-empty so the aggregation does not trigger the null pointer dereference.

Event History

May 7, 2026
CVE Published
via MITRE·04:12 AM
Data Sourced
via MITRE·04:12 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 23, 58334
Event
via FIRST·04:30 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-8063?

The severity of CVE-2026-8063 is categorized as high due to the potential for a denial-of-service attack resulting from a null pointer dereference.

2

How do I fix CVE-2026-8063?

To fix CVE-2026-8063, upgrade MongoDB Server to version 8.2.7 or later where this vulnerability has been addressed.

3

Who is affected by CVE-2026-8063?

CVE-2026-8063 affects authenticated users of MongoDB Server versions prior to 8.2.7 when using aggregation against a view with an empty pipeline.

4

What can an attacker do with CVE-2026-8063?

An attacker can exploit CVE-2026-8063 to crash the MongoDB server by executing specific aggregation commands with an empty search pipeline.

5

Is there a workaround for CVE-2026-8063?

A temporary workaround for CVE-2026-8063 is to avoid using the $rankFusion or $scoreFusion commands with empty pipelines until an upgrade is possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203