Executive brief
MongoDB Server is a widely-used NoSQL database that organizations rely on for core application data storage. This vulnerability allows an authenticated user with write permissions to crash the database server by sending specially crafted write commands, and because the crash state persists on disk, the server will repeatedly fail to restart. This results in complete service unavailability until manual database repair is performed.
Technical details
The vulnerability exists in MongoDB's handling of the stmtIds (statement IDs) field in retryable write commands. The stmtIds field is not properly validated to contain distinct IDs during command parsing; validation only occurs later in invariant assertions on the write path. For normal writes, this causes a crash before data is written; however, for time-series collections, the validation occurs in an onCommit callback after the write has been persisted to disk, causing a durable crash state. An authenticated attacker with write privileges can send specially crafted retryable write commands with duplicate or invalid stmtIds to trigger a fatal assertion crash. The persistent crash state causes the server to repeatedly crash on restart and may propagate failures across nodes in a sharded cluster. Patches are available in MongoDB versions 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2, 9.1.0-rc0, and later.
Affected products
- MongoDB MongoDB Server before 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2, 9.1.0-rc0
Timeline
- 2026-09-08: disclosed: CVE-2026-82068 published
- 2026-09-08: patched: Fixes available in versions 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2, 9.1.0-rc0