CVE-2026-8201: Use-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Encrypted Fields
A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and cryptshared. Triggering this vulnerability requires control over the structure of a client's FLE-related query.
This issue impacts MongoDB Server’s mongocryptd component v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MongoDB mongocryptd (client-side FLE query analysis)to a version that resolves this vulnerability.Fixed in 7.0.34 - Upgrade
Upgrade
MongoDB mongocryptd (client-side FLE query analysis)to a version that resolves this vulnerability.Fixed in 8.0.23 - Upgrade
Upgrade
MongoDB mongocryptd (client-side FLE query analysis)to a version that resolves this vulnerability.Fixed in 8.2.9 - Upgrade
Upgrade
MongoDB mongocryptd (client-side FLE query analysis)to a version that resolves this vulnerability.Fixed in 8.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8201?
CVE-2026-8201 is classified as a critical use-after-free vulnerability in MongoDB's Field-Level Encryption.
How do I fix CVE-2026-8201?
To fix CVE-2026-8201, update MongoDB mongocryptd to version 7.0.34, 8.0.23, 8.2.9, or later.
What versions of MongoDB are affected by CVE-2026-8201?
CVE-2026-8201 affects MongoDB mongocryptd versions prior to 7.0.34, 8.0.23, 8.2.9, and 8.3.2.
Can CVE-2026-8201 be exploited remotely?
Yes, CVE-2026-8201 can potentially be exploited remotely in client-side uses of mongocryptd.
What components of MongoDB are impacted by CVE-2026-8201?
CVE-2026-8201 impacts the Field-Level Encryption query analysis component of MongoDB.