CVE-2026-82064

A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authentication, and the assertion's assumptions about internal state do not hold for all member configurations, causing the server process to terminate.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-130759 Vendor Advisory Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

16 Sep 2026, 20:37

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/SERVER-130759 - () https://jira.mongodb.org/browse/SERVER-130759 - Vendor Advisory, Issue Tracking
First Time Mongodb
Mongodb mongodb
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

Information

Published : 2026-09-08 17:18

Updated : 2026-09-16 20:37


NVD link : CVE-2026-82064

Mitre link : CVE-2026-82064

CVE.ORG link : CVE-2026-82064


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-617

Reachable Assertion