CVE-2026-103546
Received Received - Intake

MongoDB Ops Manager Backup Configuration Validation Flaw

Vulnerability report for CVE-2026-103546, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MongoDB, Inc.

Description

In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup configuration may allow a user who can modify an OpsManager custom resource to cause unintended administrative changes in Ops Manager. This affects deployments using Enterprise Ops Manager backup reconciliation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
MongoDB, Inc. Mongodb Controllers for Kubernetes 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MongoDB Controllers for Kubernetes involves insufficient validation of Ops Manager backup configuration. A user with permission to modify an OpsManager custom resource could make unintended administrative changes in Ops Manager, specifically affecting deployments using Enterprise Ops Manager backup reconciliation.

Detection Guidance

This vulnerability involves insufficient validation of Ops Manager backup configuration in MongoDB Controllers for Kubernetes. Detection requires reviewing OpsManager custom resource configurations for unintended administrative changes. Check Kubernetes logs for unauthorized modifications to backup settings using commands like kubectl get opsmanagers -A or kubectl describe opsmanager <name> -n <namespace>.

Impact Analysis

If exploited, this vulnerability could allow unauthorized administrative changes in Ops Manager, potentially disrupting backup processes or causing misconfigurations in Kubernetes-based MongoDB deployments.

Compliance Impact

The vulnerability allows unauthorized administrative changes in Ops Manager due to insufficient validation of backup configuration. This could potentially lead to data integrity issues or unauthorized access, which may impact compliance with standards like GDPR or HIPAA by compromising data protection controls.

Mitigation Strategies

Restrict access to modify OpsManager custom resources to authorized personnel only. Review and validate all backup configurations in Ops Manager to ensure they align with intended administrative settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103546. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart