Back to VulnFeed / CVE-2026-8063
root@hackertop:~/vulnfeed/CVE-2026-8063#
CVE-2026-8063 MEDIUM CVE ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

MongoDB Server up to 8.2.6 Aggregation rankFusion/scoreFusion null pointer dereference

Server 14d ago Impact pending confirmation
LIFECYCLE
5.3 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability, which was classified as problematic, has been found in MongoDB Server up to 8.2.6 (Database Software). Affected by this issue is an unknown function of the component Aggregation Handler. Upgrading to version 8.2.7 eliminates this vulnerability.
Root Cause Analysis
The manipulation of the argument rankFusion/scoreFusion with an unknown input leads to a unknown weakness. Using CWE to declare the problem leads to CWE-476. A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Impact: Impacted is availability.

Countermeasure: Upgrading to version 8.2.7 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-8063 · CVSS 5.3 · Active Threat