CVE-2026-82066
Awaiting Analysis Awaiting Analysis - Queue

Heap Out-of-Bounds Read in MongoDB Server

Vulnerability report for CVE-2026-82066, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: MongoDB, Inc.

Description

A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can trigger the security issue through crafted query operations, causing the server to read memory beyond allocated buffer boundaries. The revealed memory contents may be partially observable through diagnostic query statistics output.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap out-of-bounds read vulnerability in MongoDB Server's query planning component. An authenticated user with read and write privileges can exploit it by sending specially crafted queries. This causes the server to read memory outside its allocated buffer, potentially exposing sensitive data through diagnostic query statistics.

Impact Analysis

If you use MongoDB Server, an attacker with database access could exploit this to read sensitive memory contents. This may lead to information disclosure, including partial data from memory that could be used for further attacks or data exfiltration.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR and HIPAA by enabling unauthorized access to sensitive data. GDPR requires protecting personal data, while HIPAA mandates safeguarding protected health information. Exploitation may lead to data breaches, resulting in legal penalties and reputational damage.

Mitigation Strategies

Update MongoDB Server to the latest patched version immediately to address the heap out-of-bounds read issue in the query planning component.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82066. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart