CVE-2026-82075
MongoDB 脆弱性の分析と軽減

概要

CVE-2026-82075 is an uncontrolled resource consumption vulnerability in the MongoDB sharded-cluster router process (mongos) that allows unauthenticated remote attackers to cause denial of service by exhausting CPU resources. The flaw affects MongoDB Server versions 7.0.0–7.0.40, 8.0.0–8.0.29, and 8.3.0–8.3.8. It was published on September 8, 2026, and is currently awaiting full NVD analysis. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Feedly, MongoDB Jira).

技術的な詳細

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), with an estimated secondary classification of CWE-400 (Uncontrolled Resource Consumption). The vulnerability exists in the request-handling path of the MongoDB sharded-cluster router (mongos): an unauthenticated client can supply specially crafted connection-monitoring parameters that trigger unbounded CPU consumption on the router process without any rate limiting or throttling mechanism in place. No authentication, elevated privileges, or user interaction is required, and the attack is network-accessible with low complexity, making it automatable (Feedly, MongoDB Jira).

影響

Successful exploitation degrades or completely denies service to legitimate clients connecting through the affected mongos router. Only availability is impacted — data confidentiality and integrity are not affected, meaning attackers cannot read, modify, or exfiltrate data through this vulnerability. In sharded MongoDB deployments, a sustained attack against the router process could render the entire cluster inaccessible to applications, causing significant operational disruption (Feedly).

エクスプロイト可能性

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.003 (0.3%), indicating a currently low probability of exploitation in the near term. The NVD SSVC assessment notes the attack is automatable with partial technical impact, and no CISA KEV catalog entry exists for this CVE. Nessus detection plugin 344382 has been released to identify vulnerable instances (Feedly, Tenable).

エクスプロイテーションのステップ

  1. Reconnaissance: Identify internet-facing or network-accessible MongoDB sharded-cluster router (mongos) instances on their default port (27017) using tools like Shodan, Censys, or nmap, targeting versions 7.0.0–7.0.40, 8.0.0–8.0.29, or 8.3.0–8.3.8.
  2. Connect without authentication: Establish a network connection to the mongos router port — no credentials are required.
  3. Supply malicious connection-monitoring parameters: Send crafted requests containing connection-monitoring parameters designed to trigger excessive CPU processing on the router without rate limiting.
  4. Sustain the attack: Repeat or parallelize the requests to continuously consume CPU resources on the mongos process, degrading or denying service to legitimate clients.

Note: Specific payload details have not been publicly disclosed. The above is based on the vulnerability description and general attack patterns for CWE-770/CWE-400 class vulnerabilities (Feedly, MongoDB Jira).

妥協の兆候

  • Network: Unusual volume of unauthenticated connections to the mongos router port (default 27017) from unexpected source IPs; high-frequency connection attempts without subsequent authenticated operations.
  • Process: Sustained abnormally high CPU utilization on the mongos process without a corresponding increase in legitimate query load.
  • Logs: MongoDB diagnostic logs showing repeated connection-monitoring parameter submissions from unauthenticated clients; log entries indicating resource exhaustion or connection handling delays in the mongos process.
  • Metrics: Monitoring dashboards showing mongos CPU spikes correlated with drops in query throughput or increased client timeout errors.

軽減策と回避策

MongoDB users should upgrade to the fixed versions: 7.0.41, 8.0.30, or 8.3.9, which address the uncontrolled resource consumption in the mongos router. As a network-level workaround, restrict access to the mongos router port using firewall rules or network ACLs to allow only trusted client IP addresses, reducing the attack surface for unauthenticated connections. Deploying MongoDB with authentication enabled and enforcing network segmentation are recommended defense-in-depth measures regardless of patch status (Feedly, MongoDB Jira).

コミュニティの反応

Coverage of CVE-2026-82075 has been limited to automated vulnerability tracking platforms and security news aggregators such as SecurityOnline.info, VulDB, and CVEFeed.io shortly after publication. No notable researcher commentary, vendor blog posts beyond the Jira ticket, or significant social media discussion has been identified at this time (Feedly, SecurityOnline).

関連情報

Linuxディストリビューションの修正状況

主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。

Ubuntu

不明

bionic (esm-apps)

mongodb

不明

focal (esm-apps)

mongodb

不明

trusty (esm-infra-legacy)

mongodb

不明

xenial (esm-apps-legacy)

mongodb

不明

ソースこのレポートは AI を使用して生成されました

関連 MongoDB 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-82075HIGH8.7
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
いいえはいSep 08, 2026
CVE-2026-89099HIGH7.7
  • MongoDB logoMongoDB
  • mongodb
いいえはいSep 11, 2026
CVE-2026-82076HIGH7.1
  • MongoDB logoMongoDB
  • mongod-7.0
いいえはいSep 08, 2026
CVE-2026-82074HIGH7.1
  • MongoDB logoMongoDB
  • mongod-8.0
いいえはいSep 08, 2026
CVE-2026-88035MEDIUM5.7
  • MongoDB logoMongoDB
  • mongo-c-driver
いいえはいSep 10, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者