CVE-2026-8843: high-severity vulnerability in MongoDB Server
Calling createIndex with certain index types can crash mongod
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server. A similar issue occurs when creating "queryable_encrypted_range" indices.
This issue affects MongoDB Server v7.0 versions prior to 7.0.32, v8.0 versions prior to 8.0.21 and v8.2 versions prior to 8.2.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
MongoDB, Inc. · MongoDB ServerRelated CVEs — MongoDB Server
In the same product, most dangerous first.
CVE-2026-8053HIGHFlatBSON Duplicate Field Index DriftEPSS 0.7%CVE-2026-8336HIGHPost-authentication use-after-free error in $_internalJsEmit and mapreduce commandsEPSS 0.5%CVE-2026-8202MEDIUMPost-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operatorsEPSS 0.5%CVE-2026-8199HIGHPost-auth memory exhaustion via bitwise match expressionsEPSS 0.5%CVE-2026-8200MEDIUMSchema validation log messages may not redact user dataEPSS 0.3%CVE-2026-8201MEDIUMUse-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Encrypted FieldsEPSS 0.2%