Information Disclosure in MongoDB Server's Query Statistics Interface
CVE-2026-82069

5.1MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82069?

A security issue in MongoDB Server's query statistics serialization allows users with monitoring privileges to inadvertently access unredacted search query text from other users' operations. An improper conditional check within the serialization logic bypasses the intended data redaction mechanisms when queries are processed through the sharded cluster router. Consequently, sensitive query literals may be stored and accessed through the query statistics interface, raising concerns over user privacy and data security.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.