
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-89099 is a race condition vulnerability in the document value layer of MongoDB Server that allows concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user with ordinary read-write database privileges can trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Affected versions include MongoDB Server 7.0.x before 7.0.43, 8.0.x before 8.0.32, and 8.3.x before 8.3.11. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Feedly).
The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition). A timing window exists in MongoDB Server's document value layer where concurrent server threads can access and modify the same internal memory region without proper locking or synchronization primitives, resulting in memory corruption. Exploitation requires network access and low-privilege (read-write) database credentials, but no user interaction; the attack complexity is rated High under CVSS v3.1 due to the timing-dependent nature of race condition exploitation. The relevant issue is tracked in MongoDB's Jira as SERVER-134063 (GitHub Advisory, MongoDB Jira).
Successful exploitation can impact the confidentiality, integrity, and availability of the affected MongoDB server process. An attacker can cause server termination (denial of service) and corrupt process memory with user-influenced content, potentially enabling information disclosure or further code execution within the server process. The scope is limited to the vulnerable server process itself, with no direct impact on subsequent systems, but database unavailability and data integrity loss represent significant operational risks (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.182% (8th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable (GitHub Advisory).
MongoDB has released patched versions addressing this vulnerability: 7.0.43 (for the 7.0 branch), 8.0.32 (for the 8.0 branch), and 8.3.11 (for the 8.3 branch). Upgrading to one of these fixed versions is the primary recommended remediation. As interim mitigations, restrict database read-write privileges to only trusted users and applications, implement network segmentation to limit connectivity to MongoDB instances, and monitor server logs for unexpected crashes or memory corruption indicators (GitHub Advisory, MongoDB Jira).
Verfügbarkeit von Korrekturen in den wichtigsten Linux-Distributionen und deren Versionen.
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"