CVE-2026-82075
MongoDB Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-82075 is an uncontrolled resource consumption vulnerability in the MongoDB sharded-cluster router (mongos) process that allows unauthenticated remote attackers to cause denial of service by exhausting CPU resources. It affects MongoDB Server versions 7.0.0–7.0.40, 8.0.0–8.0.29, and 8.3.0–8.3.8, with fixed versions being 7.0.41, 8.0.30, and 8.3.9 respectively. The vulnerability was published on September 8, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Feedly, EUVD).

Dettagli tecnici

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), with an estimated overlap with CWE-400 (Uncontrolled Resource Consumption). An unauthenticated client with network access to a mongos router port can supply specially crafted connection-monitoring parameters in requests, causing the server to expend CPU resources without any rate limiting or throttling mechanism in place. No authentication, elevated privileges, or user interaction is required, and the attack is fully automatable over the network. The vulnerability is tracked upstream in MongoDB's issue tracker as SERVER-132650 (Feedly, MongoDB Jira).

Impatto

Successful exploitation results in degraded or complete denial of service to legitimate clients of the affected MongoDB sharded-cluster router, as the server's CPU resources are consumed by attacker-controlled requests. Only availability is impacted — data confidentiality and integrity are not affected, meaning attackers cannot read, modify, or exfiltrate data through this vulnerability. The impact is limited to the mongos router process and does not directly affect underlying shard nodes, though disruption of the router effectively makes the sharded cluster inaccessible to applications (Feedly).

Sfruttabilità

As of the publication date, there are no known public proof-of-concept exploits, exploit kits, or confirmed in-the-wild exploitation incidents for CVE-2026-82075 (Feedly). The NVD SSVC assessment indicates exploitation status as "none" and the EPSS score is 0.0, reflecting low current exploitation probability. However, the attack is rated as automatable with no authentication required, making it straightforward for any attacker with network access to the mongos port to attempt. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Passaggi di sfruttamento

  1. Reconnaissance: Identify internet-facing or network-accessible MongoDB mongos (sharded-cluster router) instances using tools like Shodan or Censys, targeting default port 27017 or custom configured ports, running affected versions (7.0.0–7.0.40, 8.0.0–8.0.29, or 8.3.0–8.3.8).
  2. Establish network connection: Connect to the mongos router port without authenticating — no credentials are required to reach the vulnerable request-handling path.
  3. Send malicious connection-monitoring parameters: Craft and send requests containing specially constructed connection-monitoring parameters designed to trigger excessive CPU processing within the mongos request-handling path.
  4. Sustain the attack: Repeatedly or concurrently send such requests to maintain CPU exhaustion, as there is no rate limiting to prevent this; legitimate client requests will be degraded or denied as a result (Feedly, MongoDB Jira).

Indicatori di compromesso

  • Network: Unusual volume of unauthenticated connection attempts to the mongos router port (default 27017) from a single or distributed set of source IPs; connections that do not complete a normal authentication handshake but send repeated requests.
  • Process: Sustained high CPU utilization on the mongos process without a corresponding increase in legitimate query load; mongos process appearing unresponsive or slow to handle authenticated client requests.
  • Logs: MongoDB logs showing a high rate of connection events or request processing from unauthenticated clients; log entries indicating resource pressure or timeouts in the router process around the same time as the anomalous connections.

Mitigazione e soluzioni alternative

MongoDB has released patched versions addressing this vulnerability: 7.0.41, 8.0.30, and 8.3.9. Users should upgrade their MongoDB Server installations to the appropriate fixed version as the primary remediation. As a network-level workaround, restrict access to the mongos router port using firewall rules or network ACLs to allow only trusted client IP addresses, reducing the attack surface for unauthenticated exploitation. Enabling MongoDB authentication and enforcing it at the network perimeter can also limit exposure, though the vulnerability itself does not require authentication to trigger (Feedly, MongoDB Jira).

Risorse aggiuntive

Stato della correzione della distribuzione Linux

Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.

Ubuntu

Sconosciuto

bionic (esm-apps)

mongodb

Sconosciuto

focal (esm-apps)

mongodb

Sconosciuto

trusty (esm-infra-legacy)

mongodb

Sconosciuto

xenial (esm-apps-legacy)

mongodb

Sconosciuto

FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato MongoDB Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-82075HIGH8.7
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoSep 08, 2026
CVE-2026-82076HIGH7.1
  • MongoDB logoMongoDB
  • mongodb
NoSep 08, 2026
CVE-2026-82074HIGH7.1
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoSep 08, 2026
CVE-2026-82073HIGH7.1
  • MongoDB logoMongoDB
  • mongodb
NoSep 08, 2026
CVE-2026-88035MEDIUM5.7
  • MongoDB logoMongoDB
  • mongo-c-driver
NoNoSep 10, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità