CVE-2026-89099
MongoDB Análisis y mitigación de vulnerabilidades

Vista general

CVE-2026-89099 is a race condition vulnerability in the document value layer of MongoDB Server that allows concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user with ordinary read-write database privileges can trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Affected versions include MongoDB Server 7.0.x before 7.0.43, 8.0.x before 8.0.32, and 8.3.x before 8.3.11. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Feedly).

Técnicas

The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition). A timing window exists in MongoDB Server's document value layer where concurrent server threads can access and modify the same internal memory region without proper locking or synchronization primitives, resulting in memory corruption. Exploitation requires network access and low-privilege (read-write) database credentials, but no user interaction; the attack complexity is rated High under CVSS v3.1 due to the timing-dependent nature of race condition exploitation. The relevant issue is tracked in MongoDB's Jira as SERVER-134063 (GitHub Advisory, MongoDB Jira).

Impacto

Successful exploitation can impact the confidentiality, integrity, and availability of the affected MongoDB server process. An attacker can cause server termination (denial of service) and corrupt process memory with user-influenced content, potentially enabling information disclosure or further code execution within the server process. The scope is limited to the vulnerable server process itself, with no direct impact on subsequent systems, but database unavailability and data integrity loss represent significant operational risks (GitHub Advisory, Feedly).

Explotabilidad

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.182% (8th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable (GitHub Advisory).

Mitigación y soluciones alternativas

MongoDB has released patched versions addressing this vulnerability: 7.0.43 (for the 7.0 branch), 8.0.32 (for the 8.0 branch), and 8.3.11 (for the 8.3 branch). Upgrading to one of these fixed versions is the primary recommended remediation. As interim mitigations, restrict database read-write privileges to only trusted users and applications, implement network segmentation to limit connectivity to MongoDB instances, and monitor server logs for unexpected crashes or memory corruption indicators (GitHub Advisory, MongoDB Jira).

Recursos adicionales

Estado de corrección de la distribución Linux

Arreglar la disponibilidad en las principales distribuciones de Linux y sus lanzamientos.

Ubuntu

Desconocido

bionic (esm-apps)

mongodb

Desconocido

focal (esm-apps)

mongodb

Desconocido

trusty (esm-infra-legacy)

mongodb

Desconocido

xenial (esm-apps-legacy)

mongodb

Desconocido

FuenteEste informe se generó utilizando IA

Relacionado MongoDB Vulnerabilidades:

CVE ID

Severidad

Puntuación

Tecnologías

Nombre del componente

Exploit de CISA KEV

Tiene arreglo

Fecha de publicación

CVE-2026-82075HIGH8.7
  • MongoDB logoMongoDB
  • mongodb
NoSep 08, 2026
CVE-2026-89099HIGH7.7
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoSep 11, 2026
CVE-2026-82076HIGH7.1
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoSep 08, 2026
CVE-2026-82074HIGH7.1
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoSep 08, 2026
CVE-2026-88035MEDIUM5.7
  • MongoDB logoMongoDB
  • mongo-c-driver
NoSep 10, 2026

Evaluación gratuita de vulnerabilidades

Compare su postura de seguridad en la nube

Evalúe sus prácticas de seguridad en la nube en 9 dominios de seguridad para comparar su nivel de riesgo e identificar brechas en sus defensas.

Solicitar evaluación

Recursos adicionales de Wiz

Obtén una demostración personalizada

¿Listo para ver a Wiz en acción?

"La mejor experiencia de usuario que he visto en mi vida, proporciona una visibilidad completa de las cargas de trabajo en la nube."
David EstlickCISO
"Wiz proporciona un panel único para ver lo que ocurre en nuestros entornos en la nube."
Adam FletcherJefe de Seguridad
"Sabemos que si Wiz identifica algo como crítico, en realidad lo es."
Greg PoniatowskiJefe de Gestión de Amenazas y Vulnerabilidades