Sploitus

CVE-2026-4148

No indexed exploits for CVE-2026-4148 yet

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.

Affected products
Mongodb Server, Mongodb
Mongodb
< 7.0.31, 8.0.20, 8.2.6, 8.3.0
CVSS 3.1
8.8 HIGH
EPSS
0.3% (25th percentile)
Weakness
CWE-416
NVD status
Analyzed
Published
2026-03-17
CVE-2026-4148 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-4148 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-4148 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.