Access Control Misconfiguration in MongoDB Server
CVE-2026-82059

6MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82059?

A vulnerability in MongoDB Server arises when an internal aggregation expression is improperly exposed, allowing any authenticated user to access it without the necessary restrictions. By manipulating index specifications within this expression, a user with read-only permissions can cause assertion failures in the index key generation process. In certain configurations, this failure can lead to the termination of the mongod service, resulting in denial of service for all connected clients. This incident emphasizes the critical need for robust access controls to safeguard against potential disruptions.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

MongoDB Server 8.0.0 < 8.0.30

MongoDB Server 7.0.0 < 7.0.41

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.