Authentication Material Exposure in Ops Manager by MongoDB
CVE-2026-87109

6MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
9 October 2026

What is CVE-2026-87109?

An authenticated member of an Ops Manager organization can access another member's pending authenticator enrollment seed via user-listing endpoints, particularly when the enrollment status remains unconfirmed. This scenario enables the disclosure of sensitive authentication details to another organization or project member, compromising the integrity and security of user accounts.

Affected Version(s)

Ops Manager 7.0.0 <= 7.0.23

Ops Manager 8.0.0 < 8.0.27

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.