Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability.
{
"cna_assigner": "mongodb",
"cwe_ids": [
"CWE-178"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82067.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.3.0"
},
{
"fixed": "8.3.9"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.30"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.41"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*",
"extracted_events": [
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.41"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.30"
},
{
"introduced": "8.3.0"
},
{
"fixed": "8.3.9"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82067.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"66908565863182878949263117251652046873",
"81045179624099588995371526936867447218",
"40887363166120728720864979839570738440",
"256732394880312722171336173841003327192",
"189479856184880563329078480903896694545",
"175148206283301428432002867622286913085",
"305665546638865113923099657246304323513"
],
"threshold": 0.9
},
"id": "CVE-2026-82067-7518edcc",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/11c3ed7c274d5fb7149e498323bd0377c3a2876e",
"target": {
"file": "src/mongo/util/observable_mutex_registry.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "97328004591881352222915931748724594831",
"length": 772
},
"id": "CVE-2026-82067-77577a26",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/6df23543fc9e7ee456ff05ed726b22865ea753e7",
"target": {
"file": "src/mongo/db/pipeline/document_source_list_catalog.cpp",
"function": "DocumentSourceListCatalog::createFromBson"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"165410231648936824589980198196954162537",
"136501663843339022690751043996234207290",
"285354211900527027711069075030245862327",
"118881528740665335694743800161340085998",
"36266064472550105418329813861525007356",
"16931947150780577515020757191522828473"
],
"threshold": 0.9
},
"id": "CVE-2026-82067-ba1994eb",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/6df23543fc9e7ee456ff05ed726b22865ea753e7",
"target": {
"file": "src/mongo/db/pipeline/document_source_list_catalog.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"15118513725026685067664956440423785894",
"4881464334735159279508803095757659276",
"266758334235923098891166228361922998690",
"287039910505335082692569496912566155170",
"215343628858689419312915919625353446408",
"80950900741330922061414046051663341667",
"48699755411854371597904640594615452680",
"299434378678909034395123214857676742507",
"320443038501231526517453934170620795671",
"37185450870766536639064978090208934675",
"330071214781083562802997609052830790317",
"112905490564973162584994830096370086935"
],
"threshold": 0.9
},
"id": "CVE-2026-82067-c539edfe",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/6df23543fc9e7ee456ff05ed726b22865ea753e7",
"target": {
"file": "src/mongo/db/pipeline/document_source_list_catalog.cpp"
}
}
]
"2026-09-18T08:11:09Z"