Description
An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project.
Published: 2026-10-09
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure – Authentication Material Exposure
Action: Patch
AI Analysis

Impact

An authenticated member of a MongoDB Ops Manager organization can use user-listing endpoints to retrieve another member's pending authenticator enrollment seed while that member’s enrollment is unconfirmed. This disclosure of the secret authentication material could allow the requesting member to bypass MFA or otherwise compromise the target account. The weakness is a classic Authentication Information Disclosure (CWE-201).

Affected Systems

MongoDB Ops Manager. Version information was not specified in the CNA data, so the issue applies to the release containing the vulnerable user‑listing endpoints.

Risk and Exploitability

The CVSS base score of 6.0 indicates medium severity. EPSS data is unavailable, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user within the same organization; therefore the attack surface is limited to internal members, but the exposed MFA seed could enable account takeover or bypass of security controls.

Generated by OpenCVE AI on October 9, 2026 at 07:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update or patch MongoDB Ops Manager to the latest version that resolves the user‑listing endpoint issue.
  • Immediately revoke any unconfirmed MFA enrollment seeds for members and require re‑enrollment.
  • Restrict user permissions so that only authorized personnel can access user‑listing endpoints or view enrollment information.

Generated by OpenCVE AI on October 9, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb ops Manager
Vendors & Products Mongodb
Mongodb ops Manager

Fri, 09 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
Description An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project.
Title Ops Manager Sensitive MFA Enrollment Information Exposure in User Listings
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Ops Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-09T05:56:06.397Z

Reserved: 2026-09-08T20:29:22.918Z

Link: CVE-2026-87109

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T06:17:13.140

Modified: 2026-10-09T06:17:13.140

Link: CVE-2026-87109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T07:30:18Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data