MEDIUMVulnerability

CVE-2026-8843

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server. A similar issue occurs when creating "queryable_encrypted_range" indices. This issue affects MongoDB Server v7.0 versions prior to 7.0.32, v8.0 versions prior to 8.0.21 and v8.2 versions prior to 8.2.6

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-8843
signal_observed_at
2026-09-24T18:21:38+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
published_at
2026-05-18T17:16:34.563
last_modified
2026-09-24T17:31:28.250

Related Entities (3)

HAS_WEAKNESS (1)

→[Weakness]Reachable Assertion

DESCRIBED_BY (1)

→[Source]NVD

AFFECTS_PRODUCT (1)

→[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-8843 — Ninja Signal Threat Intelligence | Ninja Signal