Security Bypass in MongoDB Server Affects Internal Replication Handling
CVE-2026-82062

7HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82062?

A vulnerability in MongoDB Server allows authenticated users with elevated internal privileges to bypass disabled feature gates in the applyOps command. By using an unintended internal replication mode value, these users can execute forbidden operations, leading to direct storage-engine writes to arbitrary internal storage tables. This flaw is significant as it compromises the integrity of the database by permitting unauthorized writes to unrelated internal metadata and other collections. The vulnerability stems from insufficient authorization checks, which only validate the operation's namespace rather than the specific storage target involved.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.