
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-82076 is an integer overflow vulnerability in the query planning component of MongoDB Server that allows an authenticated user with ordinary database-level read/write privileges to cause unbounded memory consumption, resulting in a denial of service. The vulnerability was published on September 8, 2026, and is currently awaiting full NVD analysis. Affected versions include MongoDB Server 7.0.0–7.0.40, 8.0.0–8.0.29, and 8.3.0–8.3.8. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (Feedly, EUVD).
The root cause is an integer overflow or wraparound (CWE-190) in MongoDB Server's query planning component, mapped to CAPEC-92 (Forced Integer Overflow). When a specially crafted query is submitted, the overflow bypasses an internal resource limit designed to cap memory usage during query planning, causing the server to allocate memory without bound until the process is terminated by the operating system. Exploitation requires only low-privilege, authenticated network access with no user interaction and low attack complexity. The upstream issue is tracked as SERVER-128253 in MongoDB's Jira (Feedly, MongoDB Jira).
Successful exploitation results in complete availability loss for the affected MongoDB node — the server process terminates due to memory exhaustion, causing a denial of service for all databases hosted on that node. There is no confidentiality or integrity impact; the vulnerability is purely an availability concern. Because a single node failure can affect all databases it serves, multi-tenant or shared MongoDB deployments face broader service disruption (Feedly).
As of the publication date, there are no known public proof-of-concept exploits, no reported in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The NVD SSVC assessment classifies exploitation as "none" and the attack as not automatable, reflecting the requirement for authenticated access. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term (Feedly, EUVD).
/var/log/syslog or dmesg) showing the mongod process killed due to memory exhaustion.mongod process memory consumption visible via system monitoring tools (e.g., top, htop, Prometheus metrics) preceding a crash.MongoDB has released fixed versions addressing this vulnerability: upgrade to MongoDB Server 7.0.41, 8.0.30, or 8.3.9 or later, depending on the release branch in use. Organizations unable to upgrade immediately should restrict database access to only trusted, necessary users and monitor for anomalous query patterns or memory spikes. Limiting network exposure of MongoDB instances (e.g., firewall rules, VPN-only access) reduces the attack surface by requiring an attacker to first obtain authenticated access (Feedly, EUVD).
Disponibilidade de correção em distribuições Linux principais e suas versões.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."