Description
A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled feature gate in the applyOps command by specifying an internal replication mode value that was not intended to be client-selectable. This bypass enables execution of container operations that are disabled by default in production configurations, allowing direct storage-engine writes to arbitrary internal storage tables. The authorization check for these operations validates only the operation's namespace, not the actual storage target, enabling writes to unrelated internal metadata or other collections' data.
Published: 2026-09-08
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized internal data modification
Action: Assess
AI Analysis

Impact

An authenticated MongoDB Server user with elevated internal privileges can bypass a disabled feature gate in the applyOps command by specifying an internal replication mode value that is not intended to be client‑selectable. This bypass allows execution of container operations that are disabled by default in production configurations, enabling direct storage‑engine writes to arbitrary internal storage tables. The authorization check for these operations validates only the operation’s namespace, not the actual storage target, so the attacker can write to unrelated internal metadata or other collections’ data.

Affected Systems

MongoDB Server is the affected product. No specific version range is listed in the CNA data, implying that any deployment of MongoDB Server could be vulnerable until a patch is applied. The vulnerability requires authenticated internal privileged access, so it applies to users who hold elevated internal roles within the cluster.

Risk and Exploitability

The CVSS score of 7 indicates high severity, though the EPSS score is not available and the issue is not listed in CISA KEV, suggesting limited public exploitation data. The attack vector requires internal privileged credentials, so the risk is moderate to high for organizations that have such accounts. An attacker who can gain authenticated internal privileged access can modify internal tables, potentially corrupt data, trigger a denial of service, or use the foothold for broader compromise.

Generated by OpenCVE AI on September 8, 2026 at 18:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain the latest MongoDB Server release notes and, if available, upgrade immediately so the applyOps command can no longer write to arbitrary internal tables.
  • Implement least‑privilege controls by revoking or restricting internal privileged roles that can invoke applyOps, limiting them to essential users only.
  • If an upgrade cannot be performed urgently, isolate the applyOps API by restricting network access to the MongoDB Server instance (e.g., firewall rules) and monitor traffic for anomalous applyOps activity.

Generated by OpenCVE AI on September 8, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled feature gate in the applyOps command by specifying an internal replication mode value that was not intended to be client-selectable. This bypass enables execution of container operations that are disabled by default in production configurations, allowing direct storage-engine writes to arbitrary internal storage tables. The authorization check for these operations validates only the operation's namespace, not the actual storage target, enabling writes to unrelated internal metadata or other collections' data.
Title Improper Authorization in MongoDB Server applyOps Command Allows Writes to Arbitrary Internal Storage Tables via Feature Gate Bypass
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:58:49.601Z

Reserved: 2026-08-27T22:52:09.745Z

Link: CVE-2026-82062

cve-icon Vulnrichment

Updated: 2026-09-08T17:58:45.691Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:34.970

Modified: 2026-09-16T20:36:47.630

Link: CVE-2026-82062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses