SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82063

MEDIUM · CVSS 5.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the cursor management component of MongoDB Server allows authenticated users to trigger a denial of service by causing a server process crash through improper handling of cursor operations. This issue arises under specific timing conditions, where a stale pointer to a freed resource is dereferenced during cursor cleanup. Organizations using MongoDB should prioritize addressing this vulnerability to maintain service availability and prevent potential disruptions.

CVE
CVE-2026-82063
Severity
MEDIUM
CVSS
5.3
EPSS
0.26%
MongoDB

Original NVD Description

A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing conditions during cursor operations, a stale pointer to a freed resource may be retained and subsequently dereferenced during cursor cleanup, leading to a server process crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)