Loading
A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.
Use CWE-416, Mongodb vendor hub and Mongodb product page to widen CVE-2026-4148 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-14847, CVE-2026-1848 and CVE-2026-4147 for nearby disclosures in the same product family.