Integer Overflow Vulnerability in MongoDB Server by MongoDB
CVE-2026-82076

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82076?

An integer overflow issue in the query planning component of MongoDB Server allows authenticated users with basic database privileges to bypass resource limits. By submitting specifically crafted queries, attackers can trigger unbounded memory consumption during the planning of queries, causing the server process to crash. This exploitation can lead to a denial of service, affecting the availability of all databases hosted on the compromised server.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

MongoDB Server 8.0.0 < 8.0.30

MongoDB Server 7.0.0 < 7.0.41

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.