CVE-2026-82064
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in MongoDB Server

Vulnerability report for CVE-2026-82064, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: MongoDB, Inc.

Description

A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authentication, and the assertion's assumptions about internal state do not hold for all member configurations, causing the server process to terminate.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-30
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-29
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MongoDB Server allows an unauthenticated attacker to cause a denial of service on a specific type of replica set member. The issue stems from an assertion in the read concern processing logic that can be triggered without authentication. The assertion's assumptions about internal state are not valid for all member configurations, leading the server process to crash.

Detection Guidance

Detecting this vulnerability requires checking MongoDB server logs for unexpected process terminations or assertion failures. Monitor for crashes in replica set members, particularly those running with read concern enabled. No specific commands are provided in the context.

Impact Analysis

If you use MongoDB Server with a vulnerable replica set configuration, an attacker could exploit this flaw to crash specific replica set members. This could disrupt database operations, cause data unavailability, or lead to service interruptions for applications relying on MongoDB.

Mitigation Strategies

Apply the latest MongoDB server patch immediately. Ensure all replica set members are running the patched version. Restrict network access to MongoDB servers if possible. Monitor logs for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82064. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart