CVE-2026-82071
Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process, causing a denial of service via server crash, with potential for further impact including arbitrary code execution.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
- CWE
- CWE-787
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- MongoDB MongoDB Server
Weakness type
Related vulnerabilities
- CVE-2026-0310 — PAN-OS: Buffer Overflow Vulnerability via XML Processing
- CVE-2026-56711 — VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Write via Integer Overflow in Picture Allocation
- CVE-2026-87638 — Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-87491 — Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-87621 — Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87438 — Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote...
- CVE-2026-53938 — OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)
- CVE-2026-81980 — Acrobat Reader | Out-of-bounds Write (CWE-787)