What is CVE-2026-9737?
CVE-2026-9737 is a vulnerability in MongoDB's query planning where reading the sort pattern in raw BSONObj form does not explicitly handle the meta expression case. This can lead to incorrect transformations and invariant failure, potentially causing server crashes. Users should update to the latest stable version.
Azərbaycanca: CVE-2026-9737 MongoDB-in sorğu planlamasında raw BSONObj sort pattern oxuyarkən meta ifadə halının düzgün işlənməməsi səbəbindən invariant xətasına yol aça bilir. Bu zəiflik sorğuların səhv transformasiyasına və serverin çökməsinə səbəb ola bilər. İstifadəçilərə MongoDB-ni ən son sabit versiyaya yeniləmək tövsiyə olunur.
FAQ2
What MongoDB component does CVE-2026-9737 affect?
This vulnerability occurs in MongoDB's query planning when reading the sort pattern in raw BSONObj form.
What can an attacker achieve by exploiting CVE-2026-9737?
An attacker can cause incorrect transformations and invariant failure, potentially leading to server crashes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.