SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82052

MEDIUM · CVSS 6.5 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Authenticated users with access to run aggregation pipeline stages in MongoDB are vulnerable to a flaw in the $regexFindAll expression, which can lead to server crashes under specific conditions. This vulnerability occurs when the regex match initiates in the middle of a multi-code-unit character, causing an assertion failure during query execution. Organizations using MongoDB should prioritize addressing this issue to prevent potential service disruptions.

CVE
CVE-2026-82052
Severity
MEDIUM
CVSS
6.5
EPSS
0.36%
MongoDB

Original NVD Description

The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions theĀ  regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.

Related CVEs

Other vulnerabilities affecting the same vendor(s)