← Back to CVE List
Vulnerability Intelligence Report
Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members

CVE-2026-82064

A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authentication, and the assertion's assumptions about internal state do not hold for all member configurations, causing the server process to terminate.

No Active Exploit Signals
CVSS Base Score
8.7
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-617 ↗CWE-617: Reachable Assertion

Affected Products & Versions

Vendor Product Affected Versions
MongoDB MongoDB Server 8.3.0 < 8.3.9 (affected), 8.0.0 < 8.0.30 (affected), 7.0.0 < 7.0.41 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMongoDB, Inc. · Vendor · USA
Reserved2026-08-27T22:52:29
Published2026-09-08T16:12:24
Last Updated2026-09-08T17:58:02

LINK COPIED TO CLIPBOARD