CVE-2026-82068
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands. The crash state is durably persisted, causing the server process to repeatedly crash on restart and potentially propagating to additional nodes in a sharded cluster. Manual intervention is required to restore service availability.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | MongoDB Server | 8.3.0 < 8.3.9 | affected |
| MongoDB | MongoDB Server | 8.0.0 < 8.0.30 | affected |
| MongoDB | MongoDB Server | 7.0.0 < 7.0.41 | affected |
Weaknesses
- CWE-617: CWE-617: Reachable Assertion
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.