LDAP Authorization Security Flaw in MongoDB
CVE-2026-82053
7.6HIGH
What is CVE-2026-82053?
A security issue has been identified in MongoDB's integration with LDAP authorization, where connection pooling leads to cached LDAP authentication identities persisting beyond their intended scope. Under specific configurations, subsequent authorization requests may be incorrectly processed using these stale identities, potentially subjecting users to incorrect role assignments. This misconfiguration could inadvertently grant users elevated privileges that go against the intended access control measures defined within their LDAP directory. Proper configuration and awareness are essential to mitigate these risks.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.9
MongoDB Server 8.0.0 < 8.0.30
MongoDB Server 7.0.0 < 7.0.41