CVE-2026-82071
Awaiting Analysis Awaiting Analysis - Queue

Memory Corruption in MongoDB Server via Storage Engine Configuration

Vulnerability report for CVE-2026-82071, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: MongoDB, Inc.

Description

Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process, causing a denial of service via server crash, with potential for further impact including arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MongoDB Server involves insufficient validation of storage engine configuration options. An authenticated user with write privileges can provide crafted parameters during collection creation that override internal storage metadata. This leads to an out-of-bounds memory write in the server process, causing a denial of service via server crash. There is also potential for further impact, including arbitrary code execution.

Impact Analysis

This vulnerability can cause your MongoDB server to crash, leading to a denial of service. If exploited further, it may allow arbitrary code execution, potentially compromising data integrity and confidentiality. Users with write privileges could misuse this to disrupt services or gain unauthorized access.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. A denial of service could also disrupt compliance with availability requirements in these regulations.

Mitigation Strategies

Apply the latest MongoDB server patches immediately to address the insufficient validation flaw. Restrict write privileges to trusted users only and monitor for unusual collection creation activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82071. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart