Description
A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index lifecycle operations, a raw pointer to internal text index metadata may be dereferenced after the underlying structures have been freed, leading to a server crash. An authenticated user with readWrite privileges can trigger this condition through specific concurrent text-search and index management operations, resulting in denial of service for all connected clients. This
Published: 2026-09-08
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

A race condition in MongoDB Server's text index query parsing can trigger a heap use-after-free read when handling upsert retry paths. The flaw surfaces during concurrent index lifecycle operations, causing a raw pointer to internal text index metadata to be dereferenced after the underlying structures have been freed. An authenticated user with readWrite privileges can exploit this to crash the server, resulting in a denial of service for all connected clients. This vulnerability falls under CWE‑416 and directly compromises availability rather than confidentiality or integrity.

Affected Systems

MongoDB Server is the affected product. The specific impacted versions are not listed in the advisory, so any release prior to the fix that implements proper synchronization in text index query parsing could be vulnerable.

Risk and Exploitability

The CVSS score of 6 denotes a moderate severity. EPSS information is not available, so the current exploitation probability is unknown, and the issue is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to be an authenticated user with readWrite access to a database that uses text indexes; the attacker must also trigger concurrent text search and index management operations. If the vulnerability is successfully triggered, the server will crash and deny service to all clients. This poses a moderate risk to availability for systems that lack timely patches and proper privilege controls.

Generated by OpenCVE AI on September 8, 2026 at 18:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest MongoDB Server release that resolves the race condition.
  • Restrict readWrite privileges on databases that use text indexes to only trusted users.
  • Avoid performing index creation or modification operations while concurrent text search requests are being processed.

Generated by OpenCVE AI on September 8, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index lifecycle operations, a raw pointer to internal text index metadata may be dereferenced after the underlying structures have been freed, leading to a server crash. An authenticated user with readWrite privileges can trigger this condition through specific concurrent text-search and index management operations, resulting in denial of service for all connected clients. This
Title Race Condition in MongoDB Server Text Index Query Parsing Leads to Heap Use-After-Free and Denial of Service
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T18:01:19.015Z

Reserved: 2026-08-27T22:51:09.693Z

Link: CVE-2026-82056

cve-icon Vulnrichment

Updated: 2026-09-08T18:01:15.250Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:33.570

Modified: 2026-09-16T20:35:00.040

Link: CVE-2026-82056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses