Security Bypass in MongoDB Server Affects Internal Replication Handling
CVE-2026-82062
7HIGH
What is CVE-2026-82062?
A vulnerability in MongoDB Server allows authenticated users with elevated internal privileges to bypass disabled feature gates in the applyOps command. By using an unintended internal replication mode value, these users can execute forbidden operations, leading to direct storage-engine writes to arbitrary internal storage tables. This flaw is significant as it compromises the integrity of the database by permitting unauthorized writes to unrelated internal metadata and other collections. The vulnerability stems from insufficient authorization checks, which only validate the operation's namespace rather than the specific storage target involved.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.9