Description
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Successful use of this issue may impact the confidentiality, integrity, and availability of the affected server process.
Published: 2026-09-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Patch Now
AI Analysis

Impact

A race condition in MongoDB Server’s document value layer allows concurrent server threads to access the same internal memory without proper synchronization, which can lead to memory corruption. An authenticated user with ordinary read-write rights can trigger the issue through the standard client protocol and corrupt process memory with data influenced by the attacker. This may compromise server process.

Affected Systems

MongoDB Server is affected. No specific version details are listed, so all MongoDB Server deployments could be vulnerable unless they have applied the fix for SERVER-134063.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.7, indicating a high severity. The EPSS score is < 1%, indicating a very low exploitation probabilityISA’s KEV catalog. Based on the description, the likely attack vector involves an authenticated user performing database operations that create concurrent access. While a successful exploit could result in denial of that might lead to further compromise, the exact exploitation path requires sufficient concurrency and is unlikely to be automated without the necessary privileges.

Generated by OpenCVE AI on September 21, 2026 at 04:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest MongoDB Server update that includes the fix for SERVER-134063.
  • Restrict database user privileges so that only trusted applications have read-write access to the affected database, reducing the likelihood that a malicious user can trigger concurrent access.
  • Monitor MongoDB logs for the process restarts correctly.

Generated by OpenCVE AI on September 21, 2026 at 04:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*
cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*
cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*
Vendors & Products Mongodb mongodb

Sat, 12 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Successful use of this issue may impact the confidentiality, integrity, and availability of the affected server process.
Title Race Condition in MongoDB Server Document Value Layer Leads to Memory Corruption
Weaknesses CWE-362
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-11T17:59:19.235Z

Reserved: 2026-09-10T21:32:39.519Z

Link: CVE-2026-89099

cve-icon Vulnrichment

Updated: 2026-09-11T17:59:13.465Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T18:17:00.360

Modified: 2026-09-29T19:28:34.893

Link: CVE-2026-89099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:15:08Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')