CVE-2026-89099
MongoDB Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-89099 is a race condition vulnerability in the document value layer of MongoDB Server that allows concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user with ordinary read-write database privileges can trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Affected versions include MongoDB Server 7.0.x before 7.0.43, 8.0.x before 8.0.32, and 8.3.x before 8.3.11. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Feedly).

Détails techniques

The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition). A timing window exists in MongoDB Server's document value layer where concurrent server threads can access and modify the same internal memory region without proper locking or synchronization primitives, resulting in memory corruption. Exploitation requires network access and low-privilege (read-write) database credentials, but no user interaction; the attack complexity is rated High under CVSS v3.1 due to the timing-dependent nature of race condition exploitation. The relevant issue is tracked in MongoDB's Jira as SERVER-134063 (GitHub Advisory, MongoDB Jira).

Impact

Successful exploitation can impact the confidentiality, integrity, and availability of the affected MongoDB server process. An attacker can cause server termination (denial of service) and corrupt process memory with user-influenced content, potentially enabling information disclosure or further code execution within the server process. The scope is limited to the vulnerable server process itself, with no direct impact on subsequent systems, but database unavailability and data integrity loss represent significant operational risks (GitHub Advisory, Feedly).

Exploitabilité

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.182% (8th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable (GitHub Advisory).

Atténuation et solutions de contournement

MongoDB has released patched versions addressing this vulnerability: 7.0.43 (for the 7.0 branch), 8.0.32 (for the 8.0 branch), and 8.3.11 (for the 8.3 branch). Upgrading to one of these fixed versions is the primary recommended remediation. As interim mitigations, restrict database read-write privileges to only trusted users and applications, implement network segmentation to limit connectivity to MongoDB instances, and monitor server logs for unexpected crashes or memory corruption indicators (GitHub Advisory, MongoDB Jira).

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Ubuntu

Inconnu

bionic (esm-apps)

mongodb

Inconnu

focal (esm-apps)

mongodb

Inconnu

trusty (esm-infra-legacy)

mongodb

Inconnu

xenial (esm-apps-legacy)

mongodb

Inconnu

SourceCe rapport a été généré à l’aide de l’IA

Apparenté MongoDB Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-82075HIGH8.7
  • MongoDB logoMongoDB
  • mongodb
NonOuiSep 08, 2026
CVE-2026-89099HIGH7.7
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NonOuiSep 11, 2026
CVE-2026-82076HIGH7.1
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NonOuiSep 08, 2026
CVE-2026-82074HIGH7.1
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NonOuiSep 08, 2026
CVE-2026-88035MEDIUM5.7
  • MongoDB logoMongoDB
  • mongo-c-driver
NonOuiSep 10, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités