
PEACH
Un framework di isolamento del tenant
CVE-2026-82075 is an uncontrolled resource consumption vulnerability in the MongoDB sharded-cluster router (mongos) process that allows unauthenticated remote attackers to cause denial of service by exhausting CPU resources. It affects MongoDB Server versions 7.0.0–7.0.40, 8.0.0–8.0.29, and 8.3.0–8.3.8, with fixed versions being 7.0.41, 8.0.30, and 8.3.9 respectively. The vulnerability was published on September 8, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Feedly, EUVD).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), with an estimated overlap with CWE-400 (Uncontrolled Resource Consumption). An unauthenticated client with network access to a mongos router port can supply specially crafted connection-monitoring parameters in requests, causing the server to expend CPU resources without any rate limiting or throttling mechanism in place. No authentication, elevated privileges, or user interaction is required, and the attack is fully automatable over the network. The vulnerability is tracked upstream in MongoDB's issue tracker as SERVER-132650 (Feedly, MongoDB Jira).
Successful exploitation results in degraded or complete denial of service to legitimate clients of the affected MongoDB sharded-cluster router, as the server's CPU resources are consumed by attacker-controlled requests. Only availability is impacted — data confidentiality and integrity are not affected, meaning attackers cannot read, modify, or exfiltrate data through this vulnerability. The impact is limited to the mongos router process and does not directly affect underlying shard nodes, though disruption of the router effectively makes the sharded cluster inaccessible to applications (Feedly).
As of the publication date, there are no known public proof-of-concept exploits, exploit kits, or confirmed in-the-wild exploitation incidents for CVE-2026-82075 (Feedly). The NVD SSVC assessment indicates exploitation status as "none" and the EPSS score is 0.0, reflecting low current exploitation probability. However, the attack is rated as automatable with no authentication required, making it straightforward for any attacker with network access to the mongos port to attempt. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
MongoDB has released patched versions addressing this vulnerability: 7.0.41, 8.0.30, and 8.3.9. Users should upgrade their MongoDB Server installations to the appropriate fixed version as the primary remediation. As a network-level workaround, restrict access to the mongos router port using firewall rules or network ACLs to allow only trusted client IP addresses, reducing the attack surface for unauthenticated exploitation. Enabling MongoDB authentication and enforcing it at the network perimeter can also limit exposure, though the vulnerability itself does not require authentication to trigger (Feedly, MongoDB Jira).
Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."