Description
A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authentication, and the assertion's assumptions about internal state do not hold for all member configurations, causing the server process to terminate.
Published: 2026-09-08
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability originates from an assertion in read concern processing that can be triggered by any unauthenticated network user. When the assertion’s assumptions are violated, the server process crashes, causing a denial of service for that replica set member. The flaw represents a logic error (CWE‑617) that affects availability, allowing an attacker to disrupt data replication and service continuity without needing credentials.

Affected Systems

This flaw affects MongoDB Server instances that form part of a replica set. Any replica set member that processes read concerns with the vulnerable logic may terminate when the assertion is reached. No specific version numbers are provided, so all affected builds that implement this read concern logic are at risk until patched.

Risk and Exploitability

The CVSS score of 8.7 classifies this issue as high severity, and although EPSS data is not available, the description indicates it can be exploited by simply connecting to the server without authentication. The vulnerability is not listed in the CISA KEV catalog, but the potential for widespread service disruption makes it a serious threat, especially in environments where replica sets are exposed to untrusted networks.

Generated by OpenCVE AI on September 8, 2026 at 18:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official MongoDB patch or upgrade to a version that removes the faulty assertion.
  • Restrict network access to MongoDB Server instances, limiting unauthenticated connections to a secure internal network or through a properly configured firewall.
  • Monitor server logs for assertion failures or process crashes and temporarily isolate or reboot affected replica set members until a fix is applied.

Generated by OpenCVE AI on September 8, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authentication, and the assertion's assumptions about internal state do not hold for all member configurations, causing the server process to terminate.
Title Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:58:02.243Z

Reserved: 2026-08-27T22:52:29.008Z

Link: CVE-2026-82064

cve-icon Vulnrichment

Updated: 2026-09-08T17:57:58.131Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:35.233

Modified: 2026-09-16T20:37:20.760

Link: CVE-2026-82064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses