CVE-2026-82060
Awaiting Analysis Awaiting Analysis - Queue

MongoDB Shard Key Operator Injection in Change Streams

Vulnerability report for CVE-2026-82060, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: MongoDB, Inc.

Description

In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key values in sharded collections. When change stream events for such documents were processed with the updateLookup full document mode, the crafted values were embedded into internal post-image lookup queries without proper sanitization, causing them to be interpreted as query operators rather than literal equality values. This could result in change stream consumers receiving incorrect post-image documents or encountering non-resumable fatal errors.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MongoDB involves insufficient validation of shard key values during document insertion. Authenticated users could store documents with specially crafted objects as shard key values in sharded collections. When change stream events for these documents were processed with updateLookup full document mode, the crafted values were embedded into internal queries without proper sanitization, causing them to be misinterpreted as query operators instead of literal values. This could lead to incorrect post-image documents or fatal errors.

Impact Analysis

This vulnerability could impact you by causing change stream consumers to receive incorrect data or encounter errors that prevent resuming operations. If exploited, it may lead to data integrity issues, application crashes, or unexpected behavior in systems relying on MongoDB change streams for real-time updates.

Compliance Impact

This vulnerability may impact compliance with GDPR and HIPAA by potentially exposing or corrupting sensitive data through incorrect post-image documents or fatal errors in change stream processing. Data integrity issues could lead to unauthorized access or disclosure, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Upgrade MongoDB to a patched version that addresses the shard key validation issue. Review and sanitize shard key values in sharded collections to prevent operator-shaped objects. Disable change stream events with updateLookup mode until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82060. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart