CVE-2026-82068

A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands. The crash state is durably persisted, causing the server process to repeatedly crash on restart and potentially propagating to additional nodes in a sharded cluster. Manual intervention is required to restore service availability.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-131326 Vendor Advisory Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

16 Sep 2026, 20:38

Type Values Removed Values Added
First Time Mongodb
Mongodb mongodb
References () https://jira.mongodb.org/browse/SERVER-131326 - () https://jira.mongodb.org/browse/SERVER-131326 - Vendor Advisory, Issue Tracking
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

Information

Published : 2026-09-08 17:18

Updated : 2026-09-16 20:38


NVD link : CVE-2026-82068

Mitre link : CVE-2026-82068

CVE.ORG link : CVE-2026-82068


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-617

Reachable Assertion