Description
A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing conditions during cursor operations, a stale pointer to a freed resource may be retained and subsequently dereferenced during cursor cleanup, leading to a server process crash.
Published: 2026-09-08
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A use‑after‑free flaw in MongoDB Server’s cursor management component allows an authenticated user, under precise timing during cursor operations, to cause the database to crash during cleanup of a stale pointer. The vulnerability results in a denial of service, disrupting database availability without exposing data or permitting unauthorized code execution.

Affected Systems

MongoDB Server installations are affected. No specific version range is provided, so the issue may impact any release of the server component until a patch is applied.

Risk and Exploitability

The CVSS score of 6 indicates a medium severity vulnerability. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Exploitation requires that the user be authenticated and that a timing window during cursor activity be achieved, which reduces the attack surface but still permits a DoS if the conditions are met. Overall risk is moderate; organizations should treat this as a medium‑to‑high priority if the affected database provides critical services.

Generated by OpenCVE AI on September 8, 2026 at 18:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MongoDB Server to the latest version that includes the cursor‑management fix.
  • Limit the privileges of authenticated users so they cannot trigger cursor operations that could lead to the use‑after‑free condition.
  • Set up monitoring and automated restarting of the MongoDB process to recover from accidental crashes.

Generated by OpenCVE AI on September 8, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing conditions during cursor operations, a stale pointer to a freed resource may be retained and subsequently dereferenced during cursor cleanup, leading to a server process crash.
Title Use-After-Free in MongoDB Server Cursor Management Component Leads to Denial of Service
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:58:26.114Z

Reserved: 2026-08-27T22:52:19.939Z

Link: CVE-2026-82063

cve-icon Vulnrichment

Updated: 2026-09-08T17:58:19.910Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:35.107

Modified: 2026-09-16T20:37:09.547

Link: CVE-2026-82063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses