CVE-2026-82058
Awaiting Analysis Awaiting Analysis - Queue

MongoDB JSON Schema Validation Crash via Malformed Numeric Field

Vulnerability report for CVE-2026-82058, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: MongoDB, Inc.

Description

A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON document containing an array with a malformed numeric field name fails a $jsonSchema items type constraint, the error generation path performs unsafe numeric conversion on the user-controlled field name without proper exception handling, resulting in an uncaught exception that terminates the server process. This is possible because incoming wire protocol BSON validation does not enforce that array element field names are valid, in-range numeric indices.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in MongoDB's JSON Schema validation that allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON document contains an array with a malformed numeric field name that fails a $jsonSchema items type constraint, the error handling code performs unsafe numeric conversion on the field name without proper exception handling. This causes an uncaught exception that terminates the server process.

Impact Analysis

If exploited, this vulnerability could lead to denial of service by crashing the MongoDB server. An attacker with readWrite privileges could send specially crafted BSON documents to trigger the crash, disrupting database operations and potentially causing data unavailability.

Mitigation Strategies

Apply the latest MongoDB security patch immediately to address the flaw in JSON Schema validation error handling. Ensure no unauthenticated users have readWrite privileges and restrict access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82058. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart