Looking for the vulnerability index of Invicti's legacy products?
MongoDb Reachable Assertion Vulnerability - CVE-2026-9748 - Vulnerability Database

MongoDb Reachable Assertion Vulnerability - CVE-2026-9748

Medium
Reference: CVE-2026-9748
Title: MongoDb Reachable Assertion Vulnerability
Overview:

The _internalConvertBucketIndexStats stage used PauseExecution as a way to signal quotskip this documentquot when an index stats conversion failed. But PauseExecution is not a general purpose skip mechanism but rather a TeeBuffer-internal signal used solely by facet to coordinate its sub-pipelines. When this stage is placed before facet in a pipeline TeeBuffer receives the unexpected PauseExecution from upstream and hits a hard invariant assertion crashing mongod.