CVE-2026-88035
MongoDB Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-88035 is an integer overflow vulnerability in the MongoDB C Driver that causes a buffer overwrite in the client-side SASL authentication path. An unusually large username value passes a size check that wraps around, allowing data to be copied past the end of a small buffer. The vulnerability affects MongoDB C Driver versions 2.2.0 through 2.5.3 (exclusive) and is only reachable when the optional external SASL authentication backend is compiled in and configured for use. It was published on September 10, 2026, with a CVSS v3.1 score of 4.7 (Medium) and a CVSS v4.0 score of 5.7 (Medium) (GitHub Advisory).

Detalhes técnicos

The root cause is an integer overflow or wraparound (CWE-190) in the size validation logic within the client-side authentication code path of the MongoDB C Driver. When a username of unusual length is supplied, the size check wraps around to a small or zero value, causing the driver to accept the oversized input and copy it past the end of a fixed-size stack or heap buffer — an out-of-bounds write (CWE-787 estimated). Exploitation requires: (1) a build of the driver that includes the optional external SASL authentication backend (e.g., Cyrus SASL), (2) a connection configured to use that backend, and (3) local access with the ability to influence the driver's connection settings. The vulnerability is tracked upstream as CDRIVER-6416 (GitHub Advisory).

Impacto

Successful exploitation causes the application embedding the MongoDB C Driver to terminate unexpectedly, resulting in a denial of service. The impact is limited to availability — there is no confidentiality or integrity impact, and the vulnerability does not enable code execution or data exfiltration based on current analysis. The scope is confined to the vulnerable system itself, with no downstream or lateral movement potential identified (GitHub Advisory).

Exploração

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is non-automatable and requires local access with the ability to set driver connection settings, significantly limiting the attacker pool. NVD SSVC assessment classifies exploitation as "none" (GitHub Advisory).

Mitigação e soluções alternativas

MongoDB has released a patch in C Driver version 2.5.3, which resolves the integer overflow in the SASL authentication size check. Users running versions 2.2.0 through 2.5.2 should upgrade to 2.5.3 or later. As interim mitigations: disable or avoid using the optional external SASL authentication backend if it is not required; restrict modification of driver connection settings to trusted administrators only; and validate any user-supplied input used to configure authentication parameters (GitHub Advisory).

Recursos adicionais

Status correto da distribuição Linux

Disponibilidade de correção em distribuições Linux principais e suas versões.

Debian

Fixo

bookworm

mongo-c-driver

Afetados

sid

mongo-c-driver: 2.5.3-1

Fixo

trixie

mongo-c-driver

Afetados

Ubuntu

Desconhecido

bionic (esm-apps)

mongodb

Desconhecido

focal (esm-apps)

mongodb

Desconhecido

trusty (esm-infra-legacy)

mongodb

Desconhecido

xenial (esm-apps-legacy)

mongodb

Desconhecido

OrigemEste relatório foi gerado usando IA

Relacionado MongoDB Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-82075HIGH8.7
  • MongoDB logoMongoDB
  • mongodb
NãoSimSep 08, 2026
CVE-2026-89099HIGH7.7
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NãoSimSep 11, 2026
CVE-2026-82076HIGH7.1
  • MongoDB logoMongoDB
  • mongodb
NãoSimSep 08, 2026
CVE-2026-82074HIGH7.1
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NãoSimSep 08, 2026
CVE-2026-88035MEDIUM5.7
  • MongoDB logoMongoDB
  • mongo-c-driver
NãoNãoSep 10, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades