
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-82075 is an uncontrolled resource consumption vulnerability in the MongoDB sharded-cluster router (mongos) process that allows unauthenticated remote attackers to cause denial of service by exhausting CPU resources. It affects MongoDB Server versions 7.0.0–7.0.40, 8.0.0–8.0.29, and 8.3.0–8.3.8, with fixed versions being 7.0.41, 8.0.30, and 8.3.9 respectively. The vulnerability was published on September 8, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Feedly, EUVD).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), with an estimated overlap with CWE-400 (Uncontrolled Resource Consumption). An unauthenticated client with network access to a mongos router port can supply specially crafted connection-monitoring parameters in requests, causing the server to expend CPU resources without any rate limiting or throttling mechanism in place. No authentication, elevated privileges, or user interaction is required, and the attack is fully automatable over the network. The vulnerability is tracked upstream in MongoDB's issue tracker as SERVER-132650 (Feedly, MongoDB Jira).
Successful exploitation results in degraded or complete denial of service to legitimate clients of the affected MongoDB sharded-cluster router, as the server's CPU resources are consumed by attacker-controlled requests. Only availability is impacted — data confidentiality and integrity are not affected, meaning attackers cannot read, modify, or exfiltrate data through this vulnerability. The impact is limited to the mongos router process and does not directly affect underlying shard nodes, though disruption of the router effectively makes the sharded cluster inaccessible to applications (Feedly).
As of the publication date, there are no known public proof-of-concept exploits, exploit kits, or confirmed in-the-wild exploitation incidents for CVE-2026-82075 (Feedly). The NVD SSVC assessment indicates exploitation status as "none" and the EPSS score is 0.0, reflecting low current exploitation probability. However, the attack is rated as automatable with no authentication required, making it straightforward for any attacker with network access to the mongos port to attempt. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
MongoDB has released patched versions addressing this vulnerability: 7.0.41, 8.0.30, and 8.3.9. Users should upgrade their MongoDB Server installations to the appropriate fixed version as the primary remediation. As a network-level workaround, restrict access to the mongos router port using firewall rules or network ACLs to allow only trusted client IP addresses, reducing the attack surface for unauthenticated exploitation. Enabling MongoDB authentication and enforcing it at the network perimeter can also limit exposure, though the vulnerability itself does not require authentication to trigger (Feedly, MongoDB Jira).
Disponibilidade de correção em distribuições Linux principais e suas versões.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."