Junglewise Threat Intelligence

CVE-2026-82069: MongoDB Server query statistics serialization information disclosure

CVE-2026-82069 · Severity: low · CVSS 2.7 · Published 2026-09-08

Technologies: MongoDB, MongoDB Server. Vendors: MongoDB.

Executive brief

MongoDB Server has a flaw in how it handles search query statistics on sharded clusters. Users with monitoring access can see unredacted search query text from other users' operations, potentially exposing sensitive data embedded in search queries. This bypasses MongoDB's normal data protection controls for query statistics.

Technical details

The vulnerability is an information disclosure in MongoDB Server's query statistics serialization layer when processing $search aggregation stages through a mongos router. An improper conditional check in the redaction logic fails to anonymize native $search queries, causing raw, unredacted query text to be recorded in query statistics instead of the expected anonymized form ({$search: "?object"}). The flaw only affects queries routed through mongos; direct mongod connections properly anonymize the data. An attacker requires monitoring privileges to access the query statistics interface and view the leaked query text. The issue has been fixed in versions 8.3.9, 9.0.0-rc3, and later.

Affected products

  • MongoDB MongoDB Server before 8.3.9, 9.0.0-rc3, and 9.1.0-rc0

Timeline

  • 2026-09-08: disclosed: CVE-2026-82069 published
  • 2026-09-08: patched: Fix versions released: 8.3.9, 9.0.0-rc3, 9.1.0-rc0

References

Related threats