Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-89099: MongoDB Server can crash and corrupt data

CVE-2026-89099 · published 16 days ago
Summary

MongoDB Server may let a low‑privilege user cause two internal processes to clash, corrupting memory and potentially crashing the database. This can lead to loss or alteration of data and make the service unavailable. Apply the latest MongoDB Server update or patch to stop the issue.

What to do
  • Update mongodb mongodb server to version 8.3.11 or later.
Affected software
Ecosystem VendorProductAffected versions
– mongodb mongodb server < 8.3.11
Ubuntu:Pro:14.04:LTS canonical mongodb All versions
Original advisory text
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An a...
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Successful use of this issue may impact the confidentiality, integrity, and availability of the affected server process.
Severity
9.4 Critical
CVSS 3.1: 7.5 (NVD)
CVSS 4.0: 7.7 (NVD)
Exploitation
EPSS <1%
Type
CWE-362Race Condition
Timeline
Published11 Sep 2026
Updated27 Sep 2026
First seen11 Sep 2026
Sources
CVE-2026-89099 · MITRE
Track software like this
Free during beta