Description
An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being restricted to internal cluster operations. By crafting a malformed index specification within this expression, an authenticated user with read-only privileges could trigger an assertion failure in the index key generation code path. In certain build configurations, this assertion failure results in termination of the mongod process, causing a denial of service to all connected clients.
Published: 2026-09-08
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user. An attacker who can authenticate (even with read‑only privileges) can craft a malformed index specification within that expression, causing an assertion failure in the index key generation path. In configurations where the assertion aborts the process, the mongod instance terminates, resulting in a denial of service for all connected clients.

Affected Systems

MongoDB Server is the affected product. No specific version range is provided, so all deployments that include the vulnerable internal aggregation expression are potentially impacted. The flaw is exploitable by any authenticated user, regardless of administrative rights, that has access to the aggregation framework.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate severity, and the EPSS score is not available, so the exploitation probability is unknown but likely limited to authenticated users. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with read‑only access; the attacker submits a crafted aggregation query that includes a malformed index specification, triggering the assertion failure that may terminate the mongod process.

Generated by OpenCVE AI on September 8, 2026 at 18:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest MongoDB patch or upgrade to a version that implements restricted access to the internal aggregation expression.
  • If an immediate update is not available, limit read‑only users from executing aggregation queries that can produce internal index specifications, effectively reducing the scope for exploitation.
  • Monitor mongod logs for assertion failures or sudden process termination events and ensure that process supervision or clustering can restart the service automatically.

Generated by OpenCVE AI on September 8, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being restricted to internal cluster operations. By crafting a malformed index specification within this expression, an authenticated user with read-only privileges could trigger an assertion failure in the index key generation code path. In certain build configurations, this assertion failure results in termination of the mongod process, causing a denial of service to all connected clients.
Title Improper Access Restriction of Internal Aggregation Expression in MongoDB Server Leads to Assertion Failure and Denial of Service
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:59:27.282Z

Reserved: 2026-08-27T22:51:40.217Z

Link: CVE-2026-82059

cve-icon Vulnrichment

Updated: 2026-09-08T17:59:22.883Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:34.560

Modified: 2026-09-16T20:36:07.327

Link: CVE-2026-82059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses