Improper Case Sensitivity Handling in MongoDB Server by MongoDB Inc.
CVE-2026-82067

9.2CRITICAL

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82067?

A flaw in the configuration validation process of MongoDB Server allows improper case sensitivity handling. This issue can lead to the authorization subsystem remaining disabled during server startup. As a result, an unauthenticated user with network access to the affected deployment can exploit this vulnerability to perform arbitrary administrative operations, which poses significant risks to data confidentiality, integrity, and availability.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

MongoDB Server 8.0.0 < 8.0.30

MongoDB Server 7.0.0 < 7.0.41

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.