High-Severity Vulnerability in MongoDB Server
15 September 2026
Attackers can exploit a high-severity vulnerability in MongoDB Server to gain full unauthenticated administrative access to the affected database. Patch promptly.
Background
MongoDB has released security updates to address an improper handling of case sensitivity vulnerability (CVE-2026-82067) affecting MongoDB Server. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 8.1 out of 10.
Impact
Due to improper handling of case sensitivity in the configuration validation component of MongoDB Server, the authorisation subsystem may remain disabled during server startup. An unauthenticated attacker with network access to an affected deployment could perform arbitrary administrative operations, resulting in a complete compromise of data confidentiality, integrity, and availability.
Affected Products
This vulnerability affects the following MongoDB Server versions:
MongoDB Server 7.0: versions prior to 7.0.41
MongoDB Server 8.0: versions prior to 8.0.30
MongoDB Server 8.3: versions prior to 8.3.9
Recommendations
Users and administrators of affected products are advised to update to the latest versions promptly.
References
https://nvd.nist.gov/vuln/detail/CVE-2026-82067 (opens in new tab)
https://jira.mongodb.org/browse/SERVER-131229 (opens in new tab)
https://www.mongodb.com/docs/manual/release-notes/ (opens in new tab)
