Arbitrary Command Execution Vulnerability in MongoDB Ops Manager
CVE-2026-8431

9.4CRITICAL

Key Information:

Vendor
CVE Published:
12 May 2026

What is CVE-2026-8431?

An administrative user with permissions to configure webhooks in MongoDB Ops Manager can exploit a vulnerability that allows arbitrary command execution. By crafting and triggering webhooks containing specific FreeMarker template syntax, an attacker can execute unintended commands within the system. This vulnerability affects all versions of MongoDB Ops Manager 7.0 as well as versions 8.0.22 and earlier, posing significant risks for users who have administrative access.

Affected Version(s)

Ops Manager 7.0 < 8.0.23

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.