CVE-2026-9742: Authenticate command with specific mechanism parameter can trigger server crash
When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in affected product configurations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9742?
The severity of CVE-2026-9742 is rated as high with a score of 8.2.
What impact can CVE-2026-9742 have on my system?
CVE-2026-9742 can result in a pre-auth denial-of-service, causing the server to crash.
How do I fix CVE-2026-9742?
To mitigate CVE-2026-9742, disable OIDC authentication or restrict access to the 'authenticate' command.
What software is affected by CVE-2026-9742?
CVE-2026-9742 affects MongoDB Server.
What conditions lead to the vulnerability in CVE-2026-9742?
The vulnerability occurs when specific values are set in the 'mechanism' parameter of the 'authenticate' command with OIDC authentication enabled.