CVE-2026-8431: Ops Manager RCE via webhook body
An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.
This issue affects all MongoDB Ops Manager 7.0 versions and MongoDB Ops Manager versions 8.0.22 and prior.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MongoDB Ops Managerto a version that resolves this vulnerability.Fixed in 8.0.22
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8431?
CVE-2026-8431 is considered a critical vulnerability due to the potential for remote code execution by unauthorized users.
How do I fix CVE-2026-8431?
To mitigate CVE-2026-8431, upgrade to MongoDB Ops Manager version 8.0.23 or later.
Who is affected by CVE-2026-8431?
CVE-2026-8431 affects all MongoDB Ops Manager 7.0 versions and all versions up to 8.0.22.
What type of vulnerability is CVE-2026-8431?
CVE-2026-8431 is a remote code execution vulnerability that exploits webhooks in MongoDB Ops Manager.
Can CVE-2026-8431 be exploited without authentication?
Yes, CVE-2026-8431 can be exploited by an administrative user with access to configure webhooks.