Sploitus

CVE-2026-8201

No indexed exploits for CVE-2026-8201 yet

A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability requires control over the structure of a client's FLE-related query. This issue impacts MongoDB Server’s mongocryptd component v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

Affected products
Mongodb, Mongocryptd
Mongodb
< 7.0.34, 8.0.23, 8.2.9, 8.3.2
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.1% (3th percentile)
Weakness
CWE-416
NVD status
Analyzed
Published
2026-05-13
CVE-2026-8201 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-8201 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-8201 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.