Executive brief
MongoDB's LDAP authentication system has a flaw where pooled database connections can retain stale user identities from previous logins. When a second user performs a role lookup, their authorization query may execute under a previous user's identity rather than their own, potentially granting them unintended elevated privileges. This allows authenticated users to bypass authorization controls and gain administrative access they should not have.
Technical details
The vulnerability is a privilege escalation in MongoDB's LDAP authorization integration, where pooled LDAP connections are not properly reset between operations. When a user authenticates via PLAIN mechanism and triggers a subsequent authorization query (role lookup), the connection may retain the previous user's bound identity instead of using the configured query user or anonymous bind. Root cause is in WrappedConnection's return-to-pool path and getConnectionWithOptions logic—the code incorrectly reuses connections without resetting the bind state. An authenticated user can trigger role lookup operations that execute under a stale LDAP identity, causing the LDAP directory to return group memberships and roles assigned to that previous user. Fix requires unbinding or marking connections for rebind on return to pool, and forcing anonymous rebind or query-user rebind in getConnectionWithOptions regardless of shouldBind() state. Patches are available in MongoDB 7.0.41, 8.0.30, 8.3.9, and 9.1.0-rc0 and later.
Affected products
- MongoDB MongoDB Server Before 7.0.41, 8.0.30, 8.3.9, and 9.1.0-rc0
Timeline
- 2026-09-08: disclosed: CVE published
- 2026-09-08: patched: Patches released in 7.0.41, 8.0.30, 8.3.9, 9.0.0-rc2, 9.1.0-rc0 and later