LDAP Authorization Security Flaw in MongoDB
CVE-2026-82053

7.6HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82053?

A security issue has been identified in MongoDB's integration with LDAP authorization, where connection pooling leads to cached LDAP authentication identities persisting beyond their intended scope. Under specific configurations, subsequent authorization requests may be incorrectly processed using these stale identities, potentially subjecting users to incorrect role assignments. This misconfiguration could inadvertently grant users elevated privileges that go against the intended access control measures defined within their LDAP directory. Proper configuration and awareness are essential to mitigate these risks.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

MongoDB Server 8.0.0 < 8.0.30

MongoDB Server 7.0.0 < 7.0.41

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.