CVE-2026-4147

Published: Mar 17, 2026 Last Modified: Mar 17, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 6,5
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none

Description

AI Translation Available

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.

457

Use of Uninitialized Variable

Draft
Common Consequences
Security Scopes Affected:
Availability Integrity Other Authorization
Potential Impacts:
Other
Applicable Platforms
Languages: C, C++, Not Language-Specific, Perl, PHP
View CWE Details
https://jira.mongodb.org/browse/SERVER-119317