CVE-2026-9753: Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.
Published Jun 9, 2026
·Updated
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
Affected Software
1 affected component
MongoDB MongoDB Server
Event History
Jun 9, 2026
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-9753?
CVE-2026-9753 has a severity rating of high with a score of 8.1.
2
How do I fix CVE-2026-9753?
To fix CVE-2026-9753, upgrade to a patched version of MongoDB that addresses this vulnerability.
3
What is the impact of CVE-2026-9753?
CVE-2026-9753 allows a server crash or memory out-of-bounds access due to a malformed binary diff.
4
Who can exploit CVE-2026-9753?
CVE-2026-9753 can be exploited by any authenticated user with access to the aggregate command.
5
What is the affected software for CVE-2026-9753?
CVE-2026-9753 affects MongoDB Server.