
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8431 is a FreeMarker template injection vulnerability in MongoDB Ops Manager that allows an authenticated administrative user with webhook configuration privileges to execute arbitrary commands on the server. The vulnerability was published on May 12, 2026, and affects all MongoDB Ops Manager 7.0 versions and MongoDB Ops Manager 8.0.22 and prior. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 9.4 (Critical) (GitHub Advisory, MongoDB Release Notes).
The root cause is improper neutralization of special elements used in a command (CWE-77), specifically through unsanitized FreeMarker template syntax processed within webhook configurations. An attacker with administrative access to MongoDB Ops Manager can craft a webhook payload containing malicious FreeMarker template directives; when the webhook is triggered, the template engine evaluates the injected expressions and executes arbitrary OS-level commands in the context of the Ops Manager process. Exploitation requires high privileges (administrative access to webhook configuration) but no user interaction and has low attack complexity over a network vector (GitHub Advisory).
Successful exploitation grants the attacker full remote code execution on the MongoDB Ops Manager host, with high impact to confidentiality, integrity, and availability of both the vulnerable system and subsequent systems. An attacker could exfiltrate sensitive database credentials and configuration data, modify or destroy managed MongoDB deployments, disrupt Ops Manager availability, and potentially pivot laterally to managed MongoDB clusters under Ops Manager's control (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.053% (22nd percentile), indicating a currently low probability of exploitation in the near term (GitHub Advisory).
${"freemarker.template.utility.Execute"?new()("id")} or similar FreeMarker SSTI payloads.sh, bash, cmd.exe, curl, wget, powershell) that are not part of normal Ops Manager operation.MongoDB has released a fix in MongoDB Ops Manager 8.0.23; users should upgrade to version 8.0.23 or later. All MongoDB Ops Manager 7.0 versions are affected, so users on the 7.0 branch should migrate to a patched 8.0.x release. As interim mitigations: restrict administrative access and webhook configuration permissions to only highly trusted users, monitor webhook configurations for suspicious FreeMarker template syntax, and implement network segmentation to limit access to the Ops Manager administrative interface (MongoDB Release Notes, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."