Executive brief
MongoDB Server has a flaw in how it handles search query statistics on sharded clusters. Users with monitoring access can see unredacted search query text from other users' operations, potentially exposing sensitive data embedded in search queries. This bypasses MongoDB's normal data protection controls for query statistics.
Technical details
The vulnerability is an information disclosure in MongoDB Server's query statistics serialization layer when processing $search aggregation stages through a mongos router. An improper conditional check in the redaction logic fails to anonymize native $search queries, causing raw, unredacted query text to be recorded in query statistics instead of the expected anonymized form ({$search: "?object"}). The flaw only affects queries routed through mongos; direct mongod connections properly anonymize the data. An attacker requires monitoring privileges to access the query statistics interface and view the leaked query text. The issue has been fixed in versions 8.3.9, 9.0.0-rc3, and later.
Affected products
- MongoDB MongoDB Server before 8.3.9, 9.0.0-rc3, and 9.1.0-rc0
Timeline
- 2026-09-08: disclosed: CVE-2026-82069 published
- 2026-09-08: patched: Fix versions released: 8.3.9, 9.0.0-rc3, 9.1.0-rc0