Junglewise Threat Intelligence

CVE-2026-82071: MongoDB Server out-of-bounds memory write in storage engine configuration

CVE-2026-82071 · Severity: high · CVSS 8.1 · Published 2026-09-08

Technologies: MongoDB Server, MongoDB. Vendors: MongoDB.

Executive brief

MongoDB Server contains a vulnerability in storage engine configuration validation that allows authenticated users with write privileges to craft malicious collection creation parameters. This can trigger an out-of-bounds memory write in the server process, causing the server to crash and become unavailable. In some cases, this could potentially lead to arbitrary code execution.

Technical details

The vulnerability exists in insufficient validation of storage engine configuration options, specifically in the handling of "source" and "import" strings in WiredTiger configuration. An authenticated user with write privileges can supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process. The attack requires authentication and write privileges, with attack vector being network-accessible MongoDB instances. Patches are available in versions 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2, 9.1.0-rc0, and later.

Affected products

  • MongoDB Server 7.0 before 7.0.41, 8.0 before 8.0.30, 8.2 before 8.2.13, 8.3 before 8.3.9

Timeline

  • 2026-09-08: disclosed: CVE-2026-82071 published
  • 2026-09-08: patched: Fixes released in versions 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2, 9.1.0-rc0, and later

References

Related threats