CVE-2026-82067
- EPSS 0.28%
- Veröffentlicht 08.09.2026 16:12:26
- Zuletzt bearbeitet 16.09.2026 20:38:01
Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a depl...
CVE-2026-82065
- EPSS 0.29%
- Veröffentlicht 08.09.2026 16:12:25
- Zuletzt bearbeitet 16.09.2026 20:37:30
A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of service. Insufficient validation of user-supplied storage configuration options...
CVE-2026-82064
- EPSS 0.3%
- Veröffentlicht 08.09.2026 16:12:24
- Zuletzt bearbeitet 16.09.2026 20:37:20
A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authent...
- EPSS 0.36%
- Veröffentlicht 08.09.2026 16:12:23
- Zuletzt bearbeitet 16.09.2026 20:36:47
A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled feature gate in the applyOps command by specifying an internal replication mode value that was not intended to be client-selectable...
- EPSS 0.26%
- Veröffentlicht 08.09.2026 16:12:23
- Zuletzt bearbeitet 16.09.2026 20:37:09
A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing conditions during cursor operations, a stale pointer to a freed resource may be reta...
CVE-2026-82061
- EPSS 0.3%
- Veröffentlicht 08.09.2026 16:12:22
- Zuletzt bearbeitet 16.09.2026 20:36:31
A use-after-free security issue exists in the server's query execution memory tracking subsystem. An authenticated user with read privileges can trigger a write to freed heap memory through a sequence of standard database commands, leading to server ...
CVE-2026-82060
- EPSS 0.24%
- Veröffentlicht 08.09.2026 16:12:21
- Zuletzt bearbeitet 16.09.2026 20:36:19
In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key values in sharded collections. When change stream events for...
CVE-2026-82059
- EPSS 0.26%
- Veröffentlicht 08.09.2026 16:12:20
- Zuletzt bearbeitet 16.09.2026 20:36:07
An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being restricted to internal cluster operations. By crafting a malformed index specification within this expression, a...
CVE-2026-82057
- EPSS 0.29%
- Veröffentlicht 08.09.2026 16:12:19
- Zuletzt bearbeitet 16.09.2026 20:33:52
A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process. By specifying a custom WiredTiger storage configuration option with an incompatible value during collection creati...
CVE-2026-82058
- EPSS 0.29%
- Veröffentlicht 08.09.2026 16:12:19
- Zuletzt bearbeitet 16.09.2026 20:35:28
A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON document containing an array with a malformed numeric field name fails a $jsonSchema items...