Executive brief
MongoDB Ops Manager, a tool used to manage and monitor MongoDB database deployments, is vulnerable to a security flaw that allows high-privileged users to run unauthorized commands on the server. An administrative user could exploit this by configuring malicious webhooks using specific template syntax. This could lead to a full compromise of the Ops Manager server, potentially impacting the availability and security of the managed database infrastructure.
Technical details
A command injection vulnerability (CWE-77) exists in MongoDB Ops Manager due to improper neutralization of special elements within FreeMarker template syntax used in webhook configurations. An attacker with administrative privileges can craft a webhook containing specific FreeMarker directives that, when triggered, execute arbitrary commands on the underlying host. The vulnerability affects all versions of Ops Manager 7.0 and versions 8.0.22 and prior. Remediation is available in version 8.0.23. While the attack requires high privileges (PR:H), it can be executed over the network without user interaction.
Affected products
- MongoDB Ops Manager 7.0, 8.0.22 and prior
Timeline
- 2026-05-12: disclosed: Initial publication of CVE-2026-8431
- 2026-05-12: advisory