CVE-2026-82073
MongoDB Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-82073 is an authorization bypass vulnerability in the MongoDB Server aggregation framework that allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are in use. It affects MongoDB Server versions 8.3.0 through 8.3.8 (fixed in 8.3.9). The vulnerability was published on September 8, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (Feedly, EUVD).

Dettagli tecnici

The root cause is classified as CWE-863 (Incorrect Authorization). The vulnerability stems from insufficient validation of an internal command parameter within the aggregation framework that can be set by external clients, causing a security check to be improperly skipped when Atlas Search features are active. An authenticated attacker with low privileges can craft aggregation pipeline requests that exploit this parameter to bypass view-level authorization and read data from collections they are not authorized to access. No public proof-of-concept code has been identified at this time (Feedly, MongoDB JIRA).

Impatto

Successful exploitation results in unauthorized read access to data in MongoDB collections that are protected by view-level authorization controls, representing a high confidentiality impact. There is no impact to integrity or availability. The scope is limited to the affected MongoDB Server instance, but sensitive data exposure is a significant concern, particularly in multi-tenant or shared environments where view-based access control is relied upon as a security boundary (Feedly).

Sfruttabilità

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the publication date. The NVD SSVC assessment indicates exploitation is currently "none" and the attack is not automatable, as it requires an authenticated user with at least low-level read privileges and the Atlas Search feature to be in use. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly, MongoDB JIRA).

Mitigazione e soluzioni alternative

MongoDB has released version 8.3.9 to address this vulnerability; users running MongoDB Server 8.3.0 through 8.3.8 should upgrade to 8.3.9 or later immediately. As a temporary workaround, organizations can disable or restrict access to Atlas Search features, or enforce stricter network-level access controls to limit which authenticated users can submit aggregation pipeline requests. Review and audit user privilege assignments to ensure the principle of least privilege is applied (MongoDB JIRA, Feedly).

Risorse aggiuntive

Stato della correzione della distribuzione Linux

Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.

Ubuntu

Sconosciuto

bionic (esm-apps)

mongodb

Sconosciuto

focal (esm-apps)

mongodb

Sconosciuto

trusty (esm-infra-legacy)

mongodb

Sconosciuto

xenial (esm-apps-legacy)

mongodb

Sconosciuto

FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato MongoDB Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-82075HIGH8.7
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoSep 08, 2026
CVE-2026-82071HIGH7.2
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoSep 08, 2026
CVE-2026-82076HIGH7.1
  • MongoDB logoMongoDB
  • mongodb
NoSep 08, 2026
CVE-2026-82074HIGH7.1
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoSep 08, 2026
CVE-2026-82073HIGH7.1
  • MongoDB logoMongoDB
  • mongodb
NoSep 08, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità