CVE-2026-87110
Received Received - Intake

Unauthenticated DoS via Unlimited Monitoring Requests in MongoDB Ops Manager

Vulnerability report for CVE-2026-87110, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MongoDB, Inc.

Description

An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other traffic served by the same process while requests continue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
MongoDB Ops Manager 7.0.0
MongoDB Ops Manager 8.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated user to repeatedly access monitoring endpoints in MongoDB Ops Manager without rate limiting. These endpoints perform resource-intensive operations, which can slow down other services running on the same process while the requests continue.

Detection Guidance

Monitor network traffic to the Ops Manager web port for repeated requests to monitoring endpoints. Check server logs for unusual spikes in requests to these endpoints. Use tools like tcpdump or Wireshark to capture and analyze traffic patterns.

Impact Analysis

The impact includes degraded performance for other services sharing the same process due to high resource consumption. This could lead to slower response times or temporary unavailability of critical functions.

Mitigation Strategies

Apply rate limiting to the monitoring endpoints in Ops Manager. Restrict network access to the Ops Manager web port if possible. Update to the latest version of MongoDB Ops Manager if a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87110. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart