CVE-2026-8053: “We don’t use time-series” is not a mitigation (opens in new tab)
TL;DR: A bug in MongoDB’s time-series collection code allows a user with the standard readWrite role to corrupt memory within the mongod process. Best case: your database crashes, and you spend the night writing a postmortem. Worst case: an attacker is running their code as mongod, with the same access to your data that the … Continued The post CVE-2026-8053: “We don’t use time-series” is not a mitigation appeared first on Percona.
Read the original article