
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-82073 is an authorization bypass vulnerability in the MongoDB Server aggregation framework that allows an authenticated user with limited read privileges to access data from unauthorized collections when Atlas Search features are in use. It affects MongoDB Server versions 8.3.0 through 8.3.8 (fixed in 8.3.9). The vulnerability was published on September 8, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (Feedly, MongoDB Jira).
The root cause is classified as CWE-863 (Incorrect Authorization). The vulnerability stems from insufficient validation of an internal command parameter within the aggregation framework that can be set by external clients, causing a view-level authorization security check to be improperly skipped when Atlas Search features are active. An authenticated attacker with low privileges can craft aggregation pipeline requests that exploit this parameter to bypass view-level access controls and read data from collections they are not authorized to access. No user interaction is required, and the attack is conducted over the network with low complexity (Feedly, MongoDB Jira).
Successful exploitation results in a high confidentiality impact, allowing an attacker to read data from MongoDB collections that their account is not authorized to access, effectively bypassing view-level access controls. There is no impact on integrity or availability. The scope is limited to the affected MongoDB Server instance, but sensitive data exposure is a significant concern, particularly in multi-tenant or Atlas Search-enabled deployments where view-based access control is relied upon as a security boundary (Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of publication. The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The EPSS score is approximately 0.263%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid credentials with at least limited read privileges and an environment where Atlas Search features are enabled (Feedly).
$search or Atlas Search stage usage in aggregation pipelines from restricted accounts.MongoDB has released version 8.3.9 to address this vulnerability; administrators should upgrade all affected MongoDB Server instances from versions 8.3.0–8.3.8 to 8.3.9 or later as the primary remediation (MongoDB Jira). As a temporary workaround, organizations can consider disabling Atlas Search features if they are not required, or restricting network access to MongoDB instances to trusted clients only. Review and audit user privilege assignments to minimize the blast radius of any potential exploitation.
Coverage of CVE-2026-82073 has been limited to automated vulnerability tracking platforms and security aggregators such as SecurityOnline, VulDB, and Tenable's Nessus plugin database (plugin 344374). No notable researcher commentary or significant social media discussion has been identified at this time (Tenable Nessus, SecurityOnline).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."