CVE-2026-82067: Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments are exposed when the configuration validation case-sensitivity condition causes authorization to remain disabled during server startup. An attacker must have network access to the affected deployment.
Does an attacker need credentials or user interaction?
No. The vulnerability can be exploited by an unauthenticated attacker, and no user interaction is required.
What can an attacker do if authorization remains disabled?
An unauthenticated network-accessible attacker can perform arbitrary administrative operations. This can fully compromise data confidentiality, integrity, and availability.