---
id: CVE-2026-9737
title: >-
  During query planning when reading the sort pattern in raw BSONObj form, in
  some places we don’t explicitly handle the meta expression case
summary: >-
  During query planning when reading the sort pattern in raw BSONObj form, in
  some places we don’t explicitly handle the meta expression case. This may lead
  to incorrect transformations leading to invariant failure.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-617
vendor: mongodb
product: mongodb
affected:
  - 'mongodb >= 7.0.0, < 7.0.39'
  - 'mongodb >= 8.0.0, < 8.0.28'
  - 'mongodb >= 8.2.0, <= 8.2.12'
  - 'mongodb >= 8.3.0, < 8.3.7'
  - mongodb = 9.0.0
  - mongodb = 9.1.0
patched:
  - mongodb 8.3.7
published: '2026-07-22'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T13:07:44.260'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9737'
references:
  - url: 'https://jira.mongodb.org/browse/SERVER-128341'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00411
epssPercentile: 0.32907
ingestedAt: '2026-09-30T14:05:17.337Z'
---

## Overview

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.

## Affected

- `mongodb >= 7.0.0, < 7.0.39`
- `mongodb >= 8.0.0, < 8.0.28`
- `mongodb >= 8.2.0, <= 8.2.12`
- `mongodb >= 8.3.0, < 8.3.7`
- `mongodb = 9.0.0`
- `mongodb = 9.1.0`

## Remediation

Upgrade past the affected range:

- `mongodb 8.3.7`
