CVE-2026-82063: Use-After-Free in MongoDB Server Cursor Management Component Leads to Denial of Service

Published Sep 8, 2026
·
Updated

A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing conditions during cursor operations, a stale pointer to a freed resource may be retained and subsequently dereferenced during cursor cleanup, leading to a server process crash.

Affected Software

1 affected component
MongoDB MongoDB Server

Event History

Sep 8, 2026
CVE Published
via MITRE·04:12 PM
Data Sourced
via MITRE·04:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Does exploitation require local access or user interaction?

No. The vector is network-accessible and requires no user interaction, but the attacker must have authenticated access with low privileges.

2

How reliable is exploitation likely to be?

The attack complexity is high because it depends on specific timing conditions during cursor operations. This indicates that authentication alone is not sufficient; the required cursor-operation race or sequence must also be achieved.

3

Is there an expected data confidentiality or integrity impact?

No confidentiality or integrity impact is indicated. The stated impact is high availability impact through a MongoDB Server process crash.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203