
PEACH
Un framework di isolamento del tenant
CVE-2026-82074 is an incorrect authorization vulnerability in the MongoDB Server aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database. Affected versions include MongoDB Server 7.0.0 through 7.0.40 and 8.0.0 through 8.0.29. The vulnerability was published on September 8, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.1 (High) (Feedly, EUVD).
The root cause is classified as CWE-863 (Incorrect Authorization), where the aggregation framework fails to correctly align the operation evaluated by the authorization subsystem with the operation actually executed. This mismatch allows a low-privileged authenticated attacker to submit a specially crafted aggregation pipeline request over the network — no user interaction or elevated privileges are required beyond basic authentication. The authorization check is effectively bypassed or misdirected, granting the attacker read access to collection data they are not authorized to view. The vulnerability is tracked internally by MongoDB under SERVER-132275 (Feedly, MongoDB Jira).
Successful exploitation results in unauthorized read access to collection data within the target MongoDB database, representing a high confidentiality impact. There is no integrity or availability impact — attackers cannot modify or delete data through this vulnerability. In environments where MongoDB collections store sensitive data (e.g., PII, credentials, financial records), exploitation could lead to significant data exposure and potential regulatory consequences (Feedly).
As of the publication date, there are no known public proof-of-concept exploits, exploit kits, or evidence of in-the-wild exploitation for CVE-2026-82074. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, suggesting exploitation requires deliberate crafting of malicious aggregation requests by an authenticated user (Feedly).
aggregate commands in the MongoDB audit log from accounts not expected to query certain collections.MongoDB users should upgrade to MongoDB Server 7.0.41 or later (for the 7.0.x branch) or 8.0.30 or later (for the 8.0.x branch) to remediate this vulnerability. As a temporary workaround, organizations should enforce the principle of least privilege and restrict network access to MongoDB instances to trusted hosts only, reducing the pool of potential authenticated attackers. Monitoring MongoDB audit logs for anomalous aggregation activity from low-privileged accounts is also recommended until patching is complete (Feedly, MongoDB Jira).
Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."