Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-82067: MongoDB Server may start without authentication enabled
CVE-2026-82067 · published 19 days ago
Summary
MongoDB Server can skip its login requirement if the configuration file uses the wrong letter case, leaving the database open at start‑up. Anyone who can reach the server over the network could then run administrative commands and see, change, or delete data. Apply the latest MongoDB Server update and verify the configuration uses the correct case for the authentication setting before restarting the service.
What to do
- Update mongodb to version 8.3.9.
- Update mongodb mongodb server to version 8.3.9 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | mongodb | mongodb server | < 8.3.9 |
| Ubuntu:Pro:14.04:LTS | canonical | mongodb | All versions |
| – | mongodb | mongodb |
>= 7.0.0, < 7.0.41 >= 8.0.0, < 8.0.30 >= 8.3.0, < 8.3.9 cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:* |
| Bitnami | – | mongodb |
>= 8.3.0, < 8.3.9 Fix: upgrade to 8.3.9
|
Original advisory text
Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability.
References
- https://jira.mongodb.org/browse/SERVER-131229 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-82067 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-82067 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-82067 URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82067... Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 8.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-178Improper Handling of Case Sensitivity
Timeline
Published8 Sep 2026
Updated27 Sep 2026
First seen8 Sep 2026
Sources
CVE-2026-82067 · NVD
CVE-2026-82067 · MITRE
UBUNTU-CVE-2026-82067 · OSV
BIT-mongodb-2026-82067 · OSV
CVE-2026-82067 · OSV
Track software like this
Free during beta