Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-82073
MongoDB vulnerability analysis and mitigation

Overview

CVE-2026-82073 is an authorization bypass vulnerability in the MongoDB Server aggregation framework that allows an authenticated user with limited read privileges to access data from unauthorized collections when Atlas Search features are in use. It affects MongoDB Server versions 8.3.0 through 8.3.8 (fixed in 8.3.9). The vulnerability was published on September 8, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (Feedly, MongoDB Jira).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization). The vulnerability stems from insufficient validation of an internal command parameter within the aggregation framework that can be set by external clients, causing a view-level authorization security check to be improperly skipped when Atlas Search features are active. An authenticated attacker with low privileges can craft aggregation pipeline requests that exploit this parameter to bypass view-level access controls and read data from collections they are not authorized to access. No user interaction is required, and the attack is conducted over the network with low complexity (Feedly, MongoDB Jira).

Impact

Successful exploitation results in a high confidentiality impact, allowing an attacker to read data from MongoDB collections that their account is not authorized to access, effectively bypassing view-level access controls. There is no impact on integrity or availability. The scope is limited to the affected MongoDB Server instance, but sensitive data exposure is a significant concern, particularly in multi-tenant or Atlas Search-enabled deployments where view-based access control is relied upon as a security boundary (Feedly).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of publication. The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The EPSS score is approximately 0.263%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid credentials with at least limited read privileges and an environment where Atlas Search features are enabled (Feedly).

Exploitation steps

  1. Reconnaissance: Identify MongoDB Server instances running versions 8.3.0–8.3.8 with Atlas Search features enabled. Obtain or possess valid credentials with limited read privileges on the target deployment.
  2. Craft malicious aggregation pipeline: Construct an aggregation pipeline command that includes the vulnerable internal command parameter, setting it in a way that causes the view-level authorization check to be skipped.
  3. Submit the request: Send the crafted aggregation request to the MongoDB Server over the network (default port 27017) using a MongoDB client or driver.
  4. Access unauthorized data: The server processes the request without performing the expected view-level authorization check, returning documents from collections the authenticated user is not normally permitted to read (Feedly, MongoDB Jira).

Indicators of compromise

  • Logs: MongoDB server logs showing aggregation pipeline commands from low-privileged users accessing collections outside their normal authorization scope; unexpected $search or Atlas Search stage usage in aggregation pipelines from restricted accounts.
  • Network: Unusual aggregation query traffic on MongoDB ports (default 27017/27018) from authenticated users with limited roles, particularly involving Atlas Search pipeline stages.
  • Behavioral: Low-privileged user accounts returning data from collections they should not have access to based on defined roles and views; anomalous read activity patterns inconsistent with the user's assigned privileges.

Mitigation and workarounds

MongoDB has released version 8.3.9 to address this vulnerability; administrators should upgrade all affected MongoDB Server instances from versions 8.3.0–8.3.8 to 8.3.9 or later as the primary remediation (MongoDB Jira). As a temporary workaround, organizations can consider disabling Atlas Search features if they are not required, or restricting network access to MongoDB instances to trusted clients only. Review and audit user privilege assignments to minimize the blast radius of any potential exploitation.

Community reactions

Coverage of CVE-2026-82073 has been limited to automated vulnerability tracking platforms and security aggregators such as SecurityOnline, VulDB, and Tenable's Nessus plugin database (plugin 344374). No notable researcher commentary or significant social media discussion has been identified at this time (Tenable Nessus, SecurityOnline).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

bionic (esm-apps)

mongodb

Unknown

focal (esm-apps)

mongodb

Unknown

trusty (esm-infra-legacy)

mongodb

Unknown

xenial (esm-apps-legacy)

mongodb

Unknown

SourceThis report was generated using AI

Related MongoDB vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-82075HIGH8.7
  • MongoDB logoMongoDB
  • mongod-8.3
NoYesSep 08, 2026
CVE-2026-89099HIGH7.7
  • MongoDB logoMongoDB
  • cpe:2.3:a:mongodb:mongodb
NoYesSep 11, 2026
CVE-2026-82076HIGH7.1
  • MongoDB logoMongoDB
  • mongod-7.0
NoYesSep 08, 2026
CVE-2026-82074HIGH7.1
  • MongoDB logoMongoDB
  • mongodb
NoYesSep 08, 2026
CVE-2026-88035MEDIUM5.7
  • MongoDB logoMongoDB
  • mongodb
NoYesSep 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management