SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82059

MEDIUM · CVSS 5.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MongoDB Server contains a vulnerability where an internal aggregation expression is improperly accessible to authenticated users, allowing those with read-only privileges to exploit it by crafting a malformed index specification. This can lead to an assertion failure in the index key generation, potentially causing the mongod process to terminate and resulting in a denial of service for all connected clients. Organizations using MongoDB should prioritize addressing this issue to prevent service disruptions.

CVE
CVE-2026-82059
Severity
MEDIUM
CVSS
5.3
EPSS
0.26%
MongoDB

Original NVD Description

An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being restricted to internal cluster operations. By crafting a malformed index specification within this expression, an authenticated user with read-only privileges could trigger an assertion failure in the index key generation code path. In certain build configurations, this assertion failure results in termination of the mongod process, causing a denial of service to all connected clients.

Related CVEs

Other vulnerabilities affecting the same vendor(s)