SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82066

MEDIUM · CVSS 4.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable to a heap out-of-bounds read issue in its query planning component, which can be exploited by authenticated users with read and write privileges through specially crafted queries. This vulnerability may allow attackers to access sensitive memory contents, potentially exposing confidential data through diagnostic outputs. Database administrators and security teams should prioritize this issue to mitigate risks associated with unauthorized data exposure.

CVE
CVE-2026-82066
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%
MongoDB

Original NVD Description

A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can trigger the security issue through crafted query operations, causing the server to read memory beyond allocated buffer boundaries. The revealed memory contents may be partially observable through diagnostic query statistics output.

Related CVEs

Other vulnerabilities affecting the same vendor(s)