CVE-2026-82071

Source
https://cve.org/CVERecord?id=CVE-2026-82071
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82071.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82071
Aliases
Downstream
Published
2026-09-08T16:12:29Z
Modified
2026-09-18T03:48:30Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Insufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds Write
Details

Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process, causing a denial of service via server crash, with potential for further impact including arbitrary code execution.

Database specific
{
    "cna_assigner":  "mongodb",
    "cwe_ids":  [
        "CWE-787"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82071.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "8.3.0"
                },
                {
                    "fixed":  "8.3.9"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/mongodb/mongo

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "8.3.0"
        },
        {
            "fixed":  "8.3.9"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

r8.*
r8.3.0
r8.3.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82071.json"