Description
Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability.
Published: 2026-09-08
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Administrative Access (Privilege Escalation)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from improper handling of case sensitivity in MongoDB Server’s configuration validation component. This defect allows the authorization subsystem to remain disabled on startup, enabling any unauthenticated user with network access to perform arbitrary administrative operations. The impact encompasses full compromise of data confidentiality, integrity, and availability, and the underlying weakness is identified as CWE‑178.

Affected Systems

MongoDB Server is the affected product. No specific version information is provided, so all releases that include the flawed configuration validation logic are potentially susceptible until a fix is applied.

Risk and Exploitability

The CVSS score of 9.2 indicates critical severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is unauthenticated network access to a MongoDB deployment where the configuration validation flaw exists, allowing an attacker to start the authentication subsystem in a disabled state and perform privileged actions. Exploitation conditions appear minimal, requiring only network connectivity to the MongoDB instance.

Generated by OpenCVE AI on September 8, 2026 at 18:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest MongoDB release that addresses the configuration validation bug.
  • Confirm that the security.authorization setting is set to true in the mongod configuration file.
  • Limit network exposure of the MongoDB service to trusted hosts or VPNs and enforce appropriate firewall rules.

Generated by OpenCVE AI on September 8, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability.
Title Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
Weaknesses CWE-178
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:54:23.911Z

Reserved: 2026-08-27T22:52:58.382Z

Link: CVE-2026-82067

cve-icon Vulnrichment

Updated: 2026-09-08T17:54:18.767Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:35.617

Modified: 2026-09-16T20:38:01.447

Link: CVE-2026-82067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity