CVE-2026-82071: Insufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds Write

Published Sep 8, 2026
·
Updated

Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process, causing a denial of service via server crash, with potential for further impact including arbitrary code execution.

Affected Software

1 affected component
MongoDB MongoDB Server

Event History

Sep 8, 2026
CVE Published
via MITRE·04:12 PM
Data Sourced
via MITRE·04:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user with write privileges is required. The issue is triggered by supplying crafted storage engine configuration parameters when creating a collection.

2

Are deployments affected by default?

Exploitation requires a user to create a collection with crafted parameters; the provided information does not indicate that ordinary collection creation without those parameters triggers the issue.

3

What is the immediate impact of successful exploitation?

A successful exploit can cause an out-of-bounds memory write in the MongoDB Server process and crash the server, resulting in denial of service. The description also identifies potential further impact, including arbitrary code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203