Description
A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON document containing an array with a malformed numeric field name fails a $jsonSchema items type constraint, the error generation path performs unsafe numeric conversion on the user-controlled field name without proper exception handling, resulting in an uncaught exception that terminates the server process. This is possible because incoming wire protocol BSON validation does not enforce that array element field names are valid, in-range numeric indices.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability originates in MongoDB’s JSON Schema validation error generation routine. When a BSON document contains an array whose element field name is a malformed numeric string and violates a $jsonSchema items type constraint, the server attempts an unsafe numeric conversion on that user‑controlled field name. Because the conversion path lacks proper exception handling, an unhandled exception is raised, causing the mongod process to terminate. An attacker only needs authenticated access with readWrite privileges; the flaw is not actionable from an unauthenticated perspective. The result is a crash of the database server, leading to a denial of service. This weakness is catalogued as CWE‑248, reflecting a failure in exception handling.

Affected Systems

The affected product is MongoDB Server, as issued by MongoDB. No specific version information is listed in the CNA data, so the vulnerability likely applies to any deployment that incorporates the JSON Schema validation component present in current releases. Administrators should verify which MongoDB version is in use and whether it includes the patched logic.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity risk with a medium‑to‑high impact. The EPSS (exploit probability) score is not available, so current data do not indicate whether the vulnerability is actively exploited, but the lack of a KEV listing suggests it has not yet been observed in the wild. The attack vector requires authentication, therefore non‑credentialed exploitation is not possible; however, once legitimate readWrite access is granted, an attacker can craft a malicious BSON document and inject it through normal database operations, leading to a server crash. The likely attack path involves appending a specially‑formed document to a collection the user has write permissions for. Because the failure terminates the entire mongod process, the resulting denial of service could be pervasive across all applications relying on that database instance.

Generated by OpenCVE AI on September 8, 2026 at 18:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest MongoDB patch or upgrade to the most recent major release that addresses the JSON Schema validation error handling flaw.
  • Restrict users with readWrite privileges to only the collections that truly require write access; if possible, remove or replace readWrite–level accounts with more narrowly scoped roles.
  • Consider disabling JSON Schema validation on collections that do not demand schema enforcement or implement application‑level checks to ensure array field names are numeric and within bounds before insertion.
  • If a patch is not immediately available, isolate the database from untrusted networks and monitor for abnormal crash logs to mitigate potential denial‑of‑service impact.

Generated by OpenCVE AI on September 8, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON document containing an array with a malformed numeric field name fails a $jsonSchema items type constraint, the error generation path performs unsafe numeric conversion on the user-controlled field name without proper exception handling, resulting in an uncaught exception that terminates the server process. This is possible because incoming wire protocol BSON validation does not enforce that array element field names are valid, in-range numeric indices.
Title Unhandled Exception in MongoDB Server JSON Schema Validation Error Generation Leads to Denial of Service
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T18:00:08.983Z

Reserved: 2026-08-27T22:51:28.186Z

Link: CVE-2026-82058

cve-icon Vulnrichment

Updated: 2026-09-08T17:59:59.279Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:34.427

Modified: 2026-09-16T20:35:28.927

Link: CVE-2026-82058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses