CVE-2026-89099
MongoDB 脆弱性の分析と軽減

概要

CVE-2026-89099 is a race condition vulnerability in the document value layer of MongoDB Server that allows concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user with ordinary read-write database privileges can trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Affected versions include MongoDB Server 7.0.x before 7.0.43, 8.0.x before 8.0.32, and 8.3.x before 8.3.11. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Feedly).

技術的な詳細

The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition). A timing window exists in MongoDB Server's document value layer where concurrent server threads can access and modify the same internal memory region without proper locking or synchronization primitives, resulting in memory corruption. Exploitation requires network access and low-privilege (read-write) database credentials, but no user interaction; the attack complexity is rated High under CVSS v3.1 due to the timing-dependent nature of race condition exploitation. The relevant issue is tracked in MongoDB's Jira as SERVER-134063 (GitHub Advisory, MongoDB Jira).

影響

Successful exploitation can impact the confidentiality, integrity, and availability of the affected MongoDB server process. An attacker can cause server termination (denial of service) and corrupt process memory with user-influenced content, potentially enabling information disclosure or further code execution within the server process. The scope is limited to the vulnerable server process itself, with no direct impact on subsequent systems, but database unavailability and data integrity loss represent significant operational risks (GitHub Advisory, Feedly).

エクスプロイト可能性

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.182% (8th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable (GitHub Advisory).

軽減策と回避策

MongoDB has released patched versions addressing this vulnerability: 7.0.43 (for the 7.0 branch), 8.0.32 (for the 8.0 branch), and 8.3.11 (for the 8.3 branch). Upgrading to one of these fixed versions is the primary recommended remediation. As interim mitigations, restrict database read-write privileges to only trusted users and applications, implement network segmentation to limit connectivity to MongoDB instances, and monitor server logs for unexpected crashes or memory corruption indicators (GitHub Advisory, MongoDB Jira).

関連情報

Linuxディストリビューションの修正状況

主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。

Ubuntu

不明

bionic (esm-apps)

mongodb

不明

focal (esm-apps)

mongodb

不明

trusty (esm-infra-legacy)

mongodb

不明

xenial (esm-apps-legacy)

mongodb

不明

ソースこのレポートは AI を使用して生成されました

関連 MongoDB 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-82075HIGH8.7
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
いいえはいSep 08, 2026
CVE-2026-89099HIGH7.7
  • MongoDB logoMongoDB
  • mongodb
いいえはいSep 11, 2026
CVE-2026-82076HIGH7.1
  • MongoDB logoMongoDB
  • mongod-7.0
いいえはいSep 08, 2026
CVE-2026-82074HIGH7.1
  • MongoDB logoMongoDB
  • mongod-8.0
いいえはいSep 08, 2026
CVE-2026-88035MEDIUM5.7
  • MongoDB logoMongoDB
  • mongo-c-driver
いいえはいSep 10, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者