product · May 17, 2026
MongoDB Security Advisory Addresses Vulnerability in Timeseries Collections
Share the canonical public link.
MongoDB published security advisory AV26-468 on May 14, 2026 to address undefined behavior when inserting data with duplicate field names into timeseries collections under CVE-2026-8053. The advisory covers affected versions from MongoDB 5.0.0 to 8.3.1 including 8.3.0 to 8.3.1, 8.2.0 to 8.2.8, 8.0.0 to 8.0.22, 7.0.0 to 7.0.33, 6.0.0 to 6.0.27, and 5.0.0 to 5.0.32. Users must review the advisory and apply necessary updates to mitigate the issue. Canadian Centre for Cyber Security issued the alert on the same date as the MongoDB announcement.