SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82064

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable to a denial of service attack, where an unauthenticated network user can exploit an assertion in the read concern processing logic, leading to the termination of the server process for certain replica set configurations. This issue poses a significant risk to the availability of affected MongoDB deployments. Organizations using MongoDB, particularly those with exposed network interfaces, should prioritize applying patches to mitigate this vulnerability.

CVE
CVE-2026-82064
Severity
HIGH
CVSS
7.5
EPSS
0.30%
MongoDB

Original NVD Description

A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authentication, and the assertion's assumptions about internal state do not hold for all member configurations, causing the server process to terminate.

Related CVEs

Other vulnerabilities affecting the same vendor(s)