SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82065

MEDIUM · CVSS 6.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MongoDB Server's storage engine is vulnerable to a denial of service attack, where an authenticated user with collection creation privileges can exploit insufficient validation of storage configuration options. This flaw allows the attacker to corrupt metadata, leading to a fatal assertion failure during diagnostic operations, which persists across server restarts and affects replication to other cluster members. Database administrators and security teams managing MongoDB environments should prioritize addressing this vulnerability to prevent potential service disruptions.

CVE
CVE-2026-82065
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%
MongoDB

Original NVD Description

A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of service. Insufficient validation of user-supplied storage configuration options permits values that, once persisted to durable metadata, trigger a fatal assertion failure when the metadata is subsequently read by diagnostic operations. The corrupted metadata persists across server restarts and is replicated to other cluster members, requiring manual operator intervention to restore service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)