CVE-2026-9753: Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.
Published Jun 9, 2026
·Updated
The $internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
Affected Software
5 affected components
MongoDB MongoDB Server
MongoDB MongoDB<7.0.35
MongoDB MongoDB>=8.0.0<8.0.24
MongoDB MongoDB>=8.2.0<8.2.10
MongoDB MongoDB>=8.3.0<8.3.3
Event History
Jun 9, 2026
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 28, 58520
Event
via FIRST·04:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-9753?
CVE-2026-9753 has a severity rating of high with a score of 8.1.
2
How do I fix CVE-2026-9753?
To fix CVE-2026-9753, upgrade to a patched version of MongoDB that addresses this vulnerability.
3
What is the impact of CVE-2026-9753?
CVE-2026-9753 allows a server crash or memory out-of-bounds access due to a malformed binary diff.
4
Who can exploit CVE-2026-9753?
CVE-2026-9753 can be exploited by any authenticated user with access to the aggregate command.
5
What is the affected software for CVE-2026-9753?
CVE-2026-9753 affects MongoDB Server.