CVE-2026-9746
Server crashes in case of the use of exchange
EPSS 0.27%
Description
When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special privileges needed. The user must be logged in to issue the statement.
How to fix CVE-2026-9746
To remediate CVE-2026-9746, upgrade the affected package to a fixed version below.
- Bitnami/mongodb—upgrade to 7.0.35 or later
Is CVE-2026-9746 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 7.0.0, < 7.0.35, >= 8.0.0, < 8.0.24, >= 8.2.0, < 8.2.10, >= 8.3.0, < 8.3.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |