SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82068

MEDIUM · CVSS 6.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable to a flaw that allows authenticated users with write privileges to induce a persistent crash by sending specially crafted retryable write commands. This results in the server entering a state that causes it to repeatedly crash upon restart, affecting service availability and potentially impacting other nodes in a sharded cluster. Organizations using MongoDB, particularly those with environments that allow authenticated write access, should prioritize addressing this vulnerability to prevent service disruptions.

CVE
CVE-2026-82068
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%
MongoDB

Original NVD Description

A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands. The crash state is durably persisted, causing the server process to repeatedly crash on restart and potentially propagating to additional nodes in a sharded cluster. Manual intervention is required to restore service availability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)