Race Condition Vulnerability in MongoDB Server
CVE-2026-89099

7.7HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
11 September 2026

What is CVE-2026-89099?

A race condition in the document value layer of MongoDB Server enables multiple concurrent server threads to access the same internal memory space without proper synchronization. This flaw permits an authenticated user with basic read-write database privileges to exploit the condition via the standard client protocol. The exploitation can result in server termination and may corrupt process memory with user-influenced content. The implications of this issue can adversely affect the confidentiality, integrity, and availability of the affected MongoDB server.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.11

MongoDB Server 8.0 < 8.0.32

MongoDB Server 7.0 < 7.0.43

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.