Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-82067

MongoDB Server: case handling in configuration validation can leave authorization disabled

Technology

MongoDB

CVSS Score

8.1 / 10.0

Affected Versions

8.3 before 8.3.9; 8.0 before 8.0.30; 7.0 before 7.0.41

Upstream Fix

8.3.9; 8.0.30; 7.0.41

Published

September 8, 2026

OSSeva Coverage

Fixed upstream

Description

Improper handling of case sensitivity in MongoDB Server's configuration validation may leave the authorization subsystem in its default disabled state at startup. An unauthenticated user with network access to an affected deployment can then perform arbitrary administrative operations. Tracked as SERVER-131229. CVSS is MongoDB's CVSS 3.1 score as the CNA.

Upstream record: NVD · CVE.org

Is your MongoDB deployment affected?

If you're running 8.3 before 8.3.9; 8.0 before 8.0.30; 7.0 before 7.0.41, you need this patch. Book a discovery call to get covered.