Persistent Crash Vulnerability in MongoDB Server
CVE-2026-82068

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82068?

A vulnerability present in MongoDB Server allows authenticated users with write privileges to execute specially crafted retryable write commands. This action can provoke a persistent fatal assertion crash within the server, which leads to continuous failures upon restart. The crash state is retained durably, which may cause the process to crash repeatedly, affecting additional nodes if operating within a sharded cluster. To mitigate this issue and restore service availability, manual intervention is necessary.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

MongoDB Server 8.0.0 < 8.0.30

MongoDB Server 7.0.0 < 7.0.41

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.