Description
A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can trigger the security issue through crafted query operations, causing the server to read memory beyond allocated buffer boundaries. The revealed memory contents may be partially observable through diagnostic query statistics output.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Partial information disclosure via out‑of‑bounds read
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a heap out‑of‑bounds read in the query planning component of MongoDB Server. An authenticated user who has read and write access to a database can craft special query operations that cause the server to read memory beyond the bounds of a buffer. The memory contents can then appear, at least in part, in the diagnostic query statistics output, exposing potentially sensitive data. This defect is classified as CWE‑125.

Affected Systems

MongoDB Server is affected. No specific product versions are listed in the data, so any installation running the MongoDB Server component before the fix is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates the susceptibility can lead to partial data exposure but does not imply remote code execution. The EPSS score is unavailable, so the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with database read/write privileges, so attack surface is limited to trusted users or compromised accounts. The exploit might be constrained by the need for diagnostic query statistics to be enabled, which can be turned off by administrators.

Generated by OpenCVE AI on September 8, 2026 at 18:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest MongoDB Server patch that addresses the query planning component out‑of‑bounds read.
  • If a patch is not immediately available, remove or minimize the privileges of users who have write access to the database, or restrict them to read‑only roles.
  • Configure the server to disable or limit diagnostic query statistics output so that even if the read occurs, the memory contents are not exposed to users.

Generated by OpenCVE AI on September 8, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can trigger the security issue through crafted query operations, causing the server to read memory beyond allocated buffer boundaries. The revealed memory contents may be partially observable through diagnostic query statistics output.
Title Heap Out-of-Bounds Read in MongoDB Server Query Planning Component
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:55:05.594Z

Reserved: 2026-08-27T22:52:48.082Z

Link: CVE-2026-82066

cve-icon Vulnrichment

Updated: 2026-09-08T17:54:39.515Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:35.490

Modified: 2026-09-16T20:37:42.113

Link: CVE-2026-82066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses