Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-82067: MongoDB Server may start without authentication enabled

CVE-2026-82067 · published 19 days ago
Summary

MongoDB Server can skip its login requirement if the configuration file uses the wrong letter case, leaving the database open at start‑up. Anyone who can reach the server over the network could then run administrative commands and see, change, or delete data. Apply the latest MongoDB Server update and verify the configuration uses the correct case for the authentication setting before restarting the service.

What to do
  • Update mongodb to version 8.3.9.
  • Update mongodb mongodb server to version 8.3.9 or later.
Affected software
Ecosystem VendorProductAffected versions
– mongodb mongodb server < 8.3.9
Ubuntu:Pro:14.04:LTS canonical mongodb All versions
– mongodb mongodb >= 7.0.0, < 7.0.41
>= 8.0.0, < 8.0.30
>= 8.3.0, < 8.3.9
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Bitnami – mongodb >= 8.3.0, < 8.3.9
Fix: upgrade to 8.3.9
Original advisory text
Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability.
Severity
9.9 Critical
CVSS 3.1: 8.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-178Improper Handling of Case Sensitivity
Timeline
Published8 Sep 2026
Updated27 Sep 2026
First seen8 Sep 2026
Track software like this
Free during beta