Contact Zero

CVE-2026-88032

mongodb java driver

score 15HIGH 8.2

Summary

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application process to terminate. Reaching the issue requires an affected reactive encryption configuration that retrieves KMS credentials on demand.

Published 2026-09-10 · first seen here 2026-10-10

Analysis & write-ups

No technical write-up from a research team yet. Contact Zero checks Unit 42, Google/Mandiant, Microsoft, Talos, CrowdStrike, Rapid7, watchTowr and others several times a day, plus NVD and CISA reference links.

Where it shows in your logs

Server or web application · Memory corruption (overflow, use-after-free) medium confidence

What to look for

Data sources

Web server and WAF logs · ATT&CK DS0015 Application Log Content

Sentinel
W3CIISLogAppServiceHTTPLogsAzureDiagnostics (Application Gateway / Front Door WAF)_Im_WebSession
Splunk
Web.Webms:iis:autoaccess_combinedWAF / proxy sourcetypes
CrowdStrike
Falcon Next-Gen SIEM: third-party web / WAF / proxy logs

Process creation · ATT&CK DS0009 Process Creation

Sentinel
DeviceProcessEventsSecurityEvent (4688)Sysmon Event ID 1_Im_ProcessCreate
Splunk
Endpoint.ProcessesXmlWinEventLog:Microsoft-Windows-Sysmon/OperationalWinEventLog:Security (4688)
CrowdStrike
ProcessRollup2SyntheticProcessRollup2

File creation · ATT&CK DS0022 File Creation

Sentinel
DeviceFileEventsSysmon Event ID 11_Im_FileEvent
Splunk
Endpoint.FilesystemSysmon Event ID 11
CrowdStrike
NewExecutableWrittenNewScriptWritten*FileWritten events

Network connections · ATT&CK DS0029 Network Connection Creation / Network Traffic Flow

Sentinel
DeviceNetworkEventsCommonSecurityLog (firewall)_Im_NetworkSession
Splunk
Network_Traffic.All_TrafficFirewall sourcetypes (pan:traffic, fortigate_traffic, cisco:asa)
CrowdStrike
NetworkConnectIP4NetworkReceiveAcceptIP4NetworkConnectIP6

A generic baseline worked out from the product type and weakness (CWE-416), not a detection. Check table and field names against your environment. Hunt queries for Sigma, Splunk, Sentinel and CrowdStrike are coming.

References