Executive brief
MongoDB Server contains a flaw in its read concern processing logic that allows unauthenticated network users to crash the database process. An attacker can remotely trigger an assertion failure on replica set members (particularly arbiter nodes), causing the server to terminate and disrupting database availability. This affects MongoDB deployments without proper network segmentation.
Technical details
The vulnerability is an incorrect assertion condition in MongoDB Server's read concern processing logic. The assertion does not account for arbiter node configurations, where internal state assumptions fail to hold. An unauthenticated attacker on the network can craft requests that trigger this assertion, causing the server process to terminate. The fix (patched in versions 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2, and 9.1.0-rc1024) adjusts the invariant condition to properly handle arbiter nodes. This is a network-reachable denial of service requiring no authentication or user interaction.
Affected products
- MongoDB MongoDB Server 7.0.0 through 7.0.40; 8.0.0 through 8.0.29; 8.2.0 through 8.2.12; 8.3.0 through 8.3.8; 9.0.0-rc0 through 9.0.0-rc1; 9.1.0-rc0 through 9.1.0-rc1023
Timeline
- 2026-09-08: disclosed: CVE published on NVD
- 2026-09-08: patched: Fixed versions released: 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2, 9.1.0-rc1024