Insufficient Validation Vulnerability in MongoDB Server by MongoDB
CVE-2026-82071

7.2HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82071?

A security vulnerability in MongoDB Server enables an authenticated user with write privileges to manipulate storage engine configuration options when creating collections. This lack of adequate validation may lead to out-of-bounds memory writes, resulting in a server crash and potential denial of service. Additionally, there is a risk of arbitrary code execution, which can have severe implications for database integrity and security. Administrators should apply the latest updates to mitigate the risk and ensure the secure operation of their MongoDB deployments.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.