CVE-2026-82059
Awaiting Analysis Awaiting Analysis - Queue

MongoDB Server Assertion Failure via Malformed Index Specification

Vulnerability report for CVE-2026-82059, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: MongoDB, Inc.

Description

An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being restricted to internal cluster operations. By crafting a malformed index specification within this expression, an authenticated user with read-only privileges could trigger an assertion failure in the index key generation code path. In certain build configurations, this assertion failure results in termination of the mongod process, causing a denial of service to all connected clients.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MongoDB Server involves an internal aggregation expression that was incorrectly made accessible to any authenticated user instead of being restricted to internal cluster operations. An attacker with read-only privileges could exploit this by crafting a malformed index specification, triggering an assertion failure in the index key generation code path. In some build configurations, this causes the mongod process to terminate, leading to a denial of service for all connected clients.

Detection Guidance

This vulnerability may be detected by monitoring for unexpected mongod process terminations or crashes, particularly after index operations. Check MongoDB logs for assertion failures related to index key generation. No specific commands are provided in the context.

Impact Analysis

If you use MongoDB Server, an attacker with read-only access could exploit this flaw to crash the database server. This would disrupt all database operations, making the system unavailable to legitimate users and applications until the server is restarted.

Compliance Impact

This vulnerability could lead to service disruption, which may violate availability requirements in GDPR and HIPAA. Downtime could result in unauthorized data access or loss, potentially breaching compliance with these regulations.

Mitigation Strategies

Upgrade MongoDB to a patched version where this issue is resolved. Restrict authenticated user privileges to the minimum required. Monitor for unusual index operations or crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82059. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart