Description
A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process. By specifying a custom WiredTiger storage configuration option with an incompatible value during collection creation, a user could cause a type confusion in the storage engine layer. When documents were subsequently read from the misconfigured collection, the resulting mismatch in expected data format led to corrupted memory interpretation and a server crash. The crafted collection configuration persists across restarts, requiring manual operator intervention to remediate.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via persistent server crash
Action: Apply Patch
AI Analysis

Impact

MongoDB Server permits an authenticated user with readWrite privileges to create a collection using the WiredTiger storage engine with a custom configuration option that has an incompatible value. During collection creation, the mismatch triggers a type confusion in the storage engine. When documents are later read from the misconfigured collection, the engine attempts to interpret data with the wrong type, leading to corrupted memory dereference and causing the mongod process to crash. The crash is not transient; the incorrect configuration persists across restarts, resulting in a repeated denial of service until an operator manually corrects the collection settings.

Affected Systems

The affected product is MongoDB Server; specific version information is not provided in the vulnerability data.

Risk and Exploitability

The flaw has a CVSS score of 7.1 and does not currently appear in CISA’s KEV catalog. A user who already has authentication with readWrite rights can trigger the crash by creating a problematic collection. Because the attack requires legitimate access to the database and a custom configuration value, it is limited to internal users or compromised credentials. The resulting server crash undermines availability, making the database unusable until the misconfiguration is removed, which imposes a moderate to high risk for environments that rely on continuous data services.

Generated by OpenCVE AI on September 8, 2026 at 18:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a MongoDB Server version that contains the fix for the persistent type confusion vulnerability (check vendor release notes for CVE‑2026‑82057).
  • Identify any collections that were created with custom WiredTiger configuration options; either remove the custom option or set it to a supported value compatible with the current MongoDB version.
  • Restart the mongod process to reload the corrected configuration, and monitor the logs for any remaining crashes or type confusion errors.

Generated by OpenCVE AI on September 8, 2026 at 18:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process. By specifying a custom WiredTiger storage configuration option with an incompatible value during collection creation, a user could cause a type confusion in the storage engine layer. When documents were subsequently read from the misconfigured collection, the resulting mismatch in expected data format led to corrupted memory interpretation and a server crash. The crafted collection configuration persists across restarts, requiring manual operator intervention to remediate.
Title Type Confusion in MongoDB Server WiredTiger Storage Engine via Custom Collection Configuration Leads to Persistent Denial of Service
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T18:00:49.492Z

Reserved: 2026-08-27T22:51:18.857Z

Link: CVE-2026-82057

cve-icon Vulnrichment

Updated: 2026-09-08T18:00:45.711Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:34.287

Modified: 2026-09-16T20:33:52.627

Link: CVE-2026-82057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:15:15Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')