Authentication Material Exposure in Ops Manager by MongoDB
CVE-2026-87109
6MEDIUM
What is CVE-2026-87109?
An authenticated member of an Ops Manager organization can access another member's pending authenticator enrollment seed via user-listing endpoints, particularly when the enrollment status remains unconfirmed. This scenario enables the disclosure of sensitive authentication details to another organization or project member, compromising the integrity and security of user accounts.
Affected Version(s)
Ops Manager 7.0.0 <= 7.0.23
Ops Manager 8.0.0 < 8.0.27