Improper Validation of Specified Type of Input in MongoDB Server - CVE-2026-9753
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and cause a denial of service.
The vulnerability exists due to improper validation of specified type of input in the $_internalApplyOplogUpdate aggregation pipeline stage when processing a document diff containing a malformed binary diff. A remote user can execute the stage with a crafted document diff to disclose sensitive information and cause a denial of service.
The stage can be executed by a user with access to the aggregate command.