Description
A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of service. Insufficient validation of user-supplied storage configuration options permits values that, once persisted to durable metadata, trigger a fatal assertion failure when the metadata is subsequently read by diagnostic operations. The corrupted metadata persists across server restarts and is replicated to other cluster members, requiring manual operator intervention to restore service.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is located in the storage engine integration layer of MongoDB Server, allowing an authenticated user with collection creation privileges to supply storage configuration options that bypass validation. The invalid options are written to durable metadata; when the metadata is later read by diagnostic operations a fatal assertion failure occurs, causing a persistent denial of service. The weakness is identified as CWE‑617 (Unchecked Input for Assembly Generation).

Affected Systems

MongoDB Server is impacted. No specific versions are cited in the advisory, so any deployed instance of MongoDB Server could potentially be affected until the issue is patched. The vulnerability requires the user to have authentication and collection creation rights.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers need authenticated access with collection creation privileges, after which they can corrupt metadata that persists across restarts and propagates to replica set members. Manual operator intervention is required to restore service, so the impact on availability is significant and remediation is time-consuming.

Generated by OpenCVE AI on September 8, 2026 at 18:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest MongoDB Server release that includes the fix for corrupted metadata.
  • Enforce a strict whitelist of allowed storage configuration values to prevent invalid options from being persisted.
  • After applying the patch and configuration controls, run diagnostic operations to verify that metadata is clean and, if corruption is detected, restore from backup and roll the changes to all cluster members.

Generated by OpenCVE AI on September 8, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of service. Insufficient validation of user-supplied storage configuration options permits values that, once persisted to durable metadata, trigger a fatal assertion failure when the metadata is subsequently read by diagnostic operations. The corrupted metadata persists across server restarts and is replicated to other cluster members, requiring manual operator intervention to restore service.
Title Insufficient Validation of Storage Configuration Options in MongoDB Server Leads to Persistent Denial of Service via Corrupted Metadata
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:50:16.782Z

Reserved: 2026-08-27T22:52:38.664Z

Link: CVE-2026-82065

cve-icon Vulnrichment

Updated: 2026-09-08T17:50:13.016Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:35.360

Modified: 2026-09-16T20:37:30.310

Link: CVE-2026-82065

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses