CVE-2026-82075
MongoDB Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-82075 is an uncontrolled resource consumption vulnerability in the MongoDB sharded-cluster router (mongos) process that allows unauthenticated remote attackers to cause denial of service by exhausting CPU resources. It affects MongoDB Server versions 7.0.0–7.0.40, 8.0.0–8.0.29, and 8.3.0–8.3.8, with fixed versions being 7.0.41, 8.0.30, and 8.3.9 respectively. The vulnerability was published on September 8, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Feedly, EUVD).

Detalhes técnicos

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), with an estimated overlap with CWE-400 (Uncontrolled Resource Consumption). An unauthenticated client with network access to a mongos router port can supply specially crafted connection-monitoring parameters in requests, causing the server to expend CPU resources without any rate limiting or throttling mechanism in place. No authentication, elevated privileges, or user interaction is required, and the attack is fully automatable over the network. The vulnerability is tracked upstream in MongoDB's issue tracker as SERVER-132650 (Feedly, MongoDB Jira).

Impacto

Successful exploitation results in degraded or complete denial of service to legitimate clients of the affected MongoDB sharded-cluster router, as the server's CPU resources are consumed by attacker-controlled requests. Only availability is impacted — data confidentiality and integrity are not affected, meaning attackers cannot read, modify, or exfiltrate data through this vulnerability. The impact is limited to the mongos router process and does not directly affect underlying shard nodes, though disruption of the router effectively makes the sharded cluster inaccessible to applications (Feedly).

Exploração

As of the publication date, there are no known public proof-of-concept exploits, exploit kits, or confirmed in-the-wild exploitation incidents for CVE-2026-82075 (Feedly). The NVD SSVC assessment indicates exploitation status as "none" and the EPSS score is 0.0, reflecting low current exploitation probability. However, the attack is rated as automatable with no authentication required, making it straightforward for any attacker with network access to the mongos port to attempt. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Etapas de exploração

  1. Reconnaissance: Identify internet-facing or network-accessible MongoDB mongos (sharded-cluster router) instances using tools like Shodan or Censys, targeting default port 27017 or custom configured ports, running affected versions (7.0.0–7.0.40, 8.0.0–8.0.29, or 8.3.0–8.3.8).
  2. Establish network connection: Connect to the mongos router port without authenticating — no credentials are required to reach the vulnerable request-handling path.
  3. Send malicious connection-monitoring parameters: Craft and send requests containing specially constructed connection-monitoring parameters designed to trigger excessive CPU processing within the mongos request-handling path.
  4. Sustain the attack: Repeatedly or concurrently send such requests to maintain CPU exhaustion, as there is no rate limiting to prevent this; legitimate client requests will be degraded or denied as a result (Feedly, MongoDB Jira).

Indicadores de compromisso

  • Network: Unusual volume of unauthenticated connection attempts to the mongos router port (default 27017) from a single or distributed set of source IPs; connections that do not complete a normal authentication handshake but send repeated requests.
  • Process: Sustained high CPU utilization on the mongos process without a corresponding increase in legitimate query load; mongos process appearing unresponsive or slow to handle authenticated client requests.
  • Logs: MongoDB logs showing a high rate of connection events or request processing from unauthenticated clients; log entries indicating resource pressure or timeouts in the router process around the same time as the anomalous connections.

Mitigação e soluções alternativas

MongoDB has released patched versions addressing this vulnerability: 7.0.41, 8.0.30, and 8.3.9. Users should upgrade their MongoDB Server installations to the appropriate fixed version as the primary remediation. As a network-level workaround, restrict access to the mongos router port using firewall rules or network ACLs to allow only trusted client IP addresses, reducing the attack surface for unauthenticated exploitation. Enabling MongoDB authentication and enforcing it at the network perimeter can also limit exposure, though the vulnerability itself does not require authentication to trigger (Feedly, MongoDB Jira).

Recursos adicionais

Status correto da distribuição Linux

Disponibilidade de correção em distribuições Linux principais e suas versões.

Ubuntu

Desconhecido

bionic (esm-apps)

mongodb

Desconhecido

focal (esm-apps)

mongodb

Desconhecido

trusty (esm-infra-legacy)

mongodb

Desconhecido

xenial (esm-apps-legacy)

mongodb

Desconhecido

OrigemEste relatório foi gerado usando IA

Relacionado MongoDB Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-82075HIGH8.7
  • MongoDB logoMongoDB
  • mongodb
NãoSimSep 08, 2026
CVE-2026-89099HIGH7.7
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NãoSimSep 11, 2026
CVE-2026-82076HIGH7.1
  • MongoDB logoMongoDB
  • mongodb
NãoSimSep 08, 2026
CVE-2026-82074HIGH7.1
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NãoSimSep 08, 2026
CVE-2026-88035MEDIUM5.7
  • MongoDB logoMongoDB
  • mongo-c-driver
NãoNãoSep 10, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades