Type Confusion Vulnerability in MongoDB
CVE-2026-82057

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82057?

A security issue has been identified in MongoDB that permits authenticated users with readWrite privileges to crash the mongod server process. This occurs when users specify an incompatible value in the WiredTiger storage configuration option during collection creation. The resulting type confusion within the storage engine layer leads to corrupted memory interpretation when accessing documents from the misconfigured collection, ultimately causing the server to crash. The misconfiguration persists through server restarts, necessitating manual intervention for resolution.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.