CVE-2026-82076
Analyzed Analyzed - Analysis Complete

Integer Overflow in MongoDB Server Leads to DoS

Vulnerability report for CVE-2026-82076, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-14

Assigner: MongoDB, Inc.

Description

An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal resource limit. Submitting a specially crafted query causes the server to consume memory without bound during query planning, and the resulting exhaustion terminates the server process. This may result in a denial of service affecting all databases served by the affected node.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
mongodb mongodb 9.0.0
mongodb mongodb 9.0.0
mongodb mongodb From 7.0.0 (inc) to 7.0.41 (exc)
mongodb mongodb From 8.0.0 (inc) to 8.0.30 (exc)
mongodb mongodb From 8.3.0 (inc) to 8.3.9 (exc)
mongodb mongodb From 8.2.0 (inc) to 8.2.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an integer overflow in MongoDB Server's query planning component. An authenticated user with read/write privileges can exploit it by submitting a specially crafted query. This causes the server to consume excessive memory during query planning, leading to a denial of service as the server process terminates due to resource exhaustion.

Detection Guidance

This vulnerability may be detected by monitoring for abnormal memory consumption during query planning in MongoDB Server. Check for server crashes or unresponsive nodes after running complex queries. Review MongoDB logs for signs of memory exhaustion or termination events.

Impact Analysis

If exploited, this vulnerability can cause a denial of service affecting all databases served by the affected MongoDB node. This means the server may crash, making data inaccessible to legitimate users until the service is restored.

Mitigation Strategies

Apply the latest MongoDB Server patch immediately. Limit database-level read/write privileges to only trusted users. Monitor memory usage and set resource limits to prevent unbounded consumption during query planning.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82076. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart