CVE-2026-82053
Undergoing Analysis Undergoing Analysis - In Progress

LDAP Identity Retention in MongoDB Authorization

Vulnerability report for CVE-2026-82053, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: MongoDB, Inc.

Description

A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privileges that were not intended by the deployment's authorization policy.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves MongoDB's LDAP authorization integration where pooled LDAP connections retain stale authentication identities after user authentication. This can cause authorization queries to execute under an unintended LDAP identity, leading to incorrect role assignments and potential privilege escalation for authenticated users.

Impact Analysis

An attacker with valid authentication could exploit this to gain elevated privileges not intended by the system's policy. This may allow unauthorized access to sensitive data or operations, depending on the LDAP directory's access control configuration.

Compliance Impact

This vulnerability could lead to unauthorized access or privilege escalation, violating data protection requirements in GDPR and HIPAA. Non-compliance may result in legal penalties, data breaches, or loss of certification.

Mitigation Strategies

Review and update MongoDB LDAP authorization configurations to ensure pooled connections are properly reset after user authentication. Restart affected MongoDB instances to clear stale LDAP identities. Monitor role assignments and privilege escalations as indicators of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82053. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart