Skip to content

CVE-2026-82067

8.1 HIGHEPSS 0.28%
  1. Published8 Sept 2026

Description

Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability.

CVSS 3.1 breakdown

Attack vectorNetwork
Attack complexityHigh
Privileges requiredNone
User interactionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

Mongodb Mongodb≥ 7.0.0 < 7.0.41 · ≥ 8.0.0 < 8.0.30 · ≥ 8.3.0 < 8.3.9

Remediation

Fixed in
Mongodb Mongodb7.0.41

References

Frequently asked

Is CVE-2026-82067 being actively exploited?

CVE-2026-82067 is not in the CISA KEV catalog. Its EPSS exploit probability is 0.28%.

How severe is CVE-2026-82067?

CVE-2026-82067 has a CVSS 3.1 base score of 8.1, rated high. EPSS estimates a 0.28% probability of exploitation.

Which products are affected by CVE-2026-82067?

Affected products include Mongodb Mongodb.

How do I fix CVE-2026-82067?

Upgrade affected software to a fixed version, for example Mongodb Mongodb 7.0.41 or later, then confirm no affected versions remain in your inventory.

How Secuno handles this

Secuno correlates vulnerabilities like CVE-2026-82067 against the real software inventory on every managed device, every day. Rather than a static severity, each match is scored in context: exploit availability, EPSS, the asset's exposure, and business criticality decide where it lands in the queue. If an affected version is present anywhere across your portfolio, it surfaces automatically with a prioritised remediation path.

Data from the NVD, CISA KEV catalog and FIRST EPSS. CVSS 3.1 base score shown where available.