Locking Mechanism Flaw in MongoDB Server by MongoDB Inc.
CVE-2026-25612

7.1HIGH

Key Information:

Vendor

MongoDB

Vendor
CVE Published:
10 February 2026

What is CVE-2026-25612?

The MongoDB Server contains a locking mechanism that may lead to resource collisions due to its internal encoding system. This flaw can result in conflicting locks between collections, affecting the availability of the server. If different collections inadvertently collide in their internal representations, it may create situations where the server is unable to process requests effectively, potentially hindering application performance and server operations. System administrators should review the locking configuration and consider implementing safeguards to mitigate these issues.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MongoDB Server 8.2 < 8.2.4

MongoDB Server 8.0 < 8.0.18

MongoDB Server 7.0 < 7.0.29

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.