Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-89099: MongoDB Server can crash and corrupt data
CVE-2026-89099 · published 16 days ago
Summary
MongoDB Server may let a low‑privilege user cause two internal processes to clash, corrupting memory and potentially crashing the database. This can lead to loss or alteration of data and make the service unavailable. Apply the latest MongoDB Server update or patch to stop the issue.
What to do
- Update mongodb mongodb server to version 8.3.11 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | mongodb | mongodb server | < 8.3.11 |
| Ubuntu:Pro:14.04:LTS | canonical | mongodb | All versions |
Original advisory text
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An a...
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Successful use of this issue may impact the confidentiality, integrity, and availability of the affected server process.
References
- https://jira.mongodb.org/browse/SERVER-134063 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-89099 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-89099 Third Party Advisory
Severity
9.4
Critical
CVSS 3.1: 7.5 (NVD)
CVSS 4.0: 7.7 (NVD)
Exploitation
EPSS <1%
Type
CWE-362Race Condition
Timeline
Published11 Sep 2026
Updated27 Sep 2026
First seen11 Sep 2026
Track software like this
Free during beta