
PEACH
Un framework di isolamento del tenant
CVE-2026-82073 is an authorization bypass vulnerability in the MongoDB Server aggregation framework that allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are in use. It affects MongoDB Server versions 8.3.0 through 8.3.8 (fixed in 8.3.9). The vulnerability was published on September 8, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (Feedly, EUVD).
The root cause is classified as CWE-863 (Incorrect Authorization). The vulnerability stems from insufficient validation of an internal command parameter within the aggregation framework that can be set by external clients, causing a security check to be improperly skipped when Atlas Search features are active. An authenticated attacker with low privileges can craft aggregation pipeline requests that exploit this parameter to bypass view-level authorization and read data from collections they are not authorized to access. No public proof-of-concept code has been identified at this time (Feedly, MongoDB JIRA).
Successful exploitation results in unauthorized read access to data in MongoDB collections that are protected by view-level authorization controls, representing a high confidentiality impact. There is no impact to integrity or availability. The scope is limited to the affected MongoDB Server instance, but sensitive data exposure is a significant concern, particularly in multi-tenant or shared environments where view-based access control is relied upon as a security boundary (Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the publication date. The NVD SSVC assessment indicates exploitation is currently "none" and the attack is not automatable, as it requires an authenticated user with at least low-level read privileges and the Atlas Search feature to be in use. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly, MongoDB JIRA).
MongoDB has released version 8.3.9 to address this vulnerability; users running MongoDB Server 8.3.0 through 8.3.8 should upgrade to 8.3.9 or later immediately. As a temporary workaround, organizations can disable or restrict access to Atlas Search features, or enforce stricter network-level access controls to limit which authenticated users can submit aggregation pipeline requests. Review and audit user privilege assignments to ensure the principle of least privilege is applied (MongoDB JIRA, Feedly).
Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."