CVE-2026-82067
MongoDB Server: case handling in configuration validation can leave authorization disabled
Technology
MongoDB
CVSS Score
8.1 / 10.0
Affected Versions
8.3 before 8.3.9; 8.0 before 8.0.30; 7.0 before 7.0.41
Upstream Fix
8.3.9; 8.0.30; 7.0.41
Published
September 8, 2026
OSSeva Coverage
Fixed upstream
Description
Improper handling of case sensitivity in MongoDB Server's configuration validation may leave the authorization subsystem in its default disabled state at startup. An unauthenticated user with network access to an affected deployment can then perform arbitrary administrative operations. Tracked as SERVER-131229. CVSS is MongoDB's CVSS 3.1 score as the CNA.
Is your MongoDB deployment affected?
If you're running 8.3 before 8.3.9; 8.0 before 8.0.30; 7.0 before 7.0.41, you need this patch. Book a discovery call to get covered.