HIGHVulnerability

CVE-2026-82071

Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process, causing a denial of service via server crash, with potential for further impact including arbitrary code execution.

Properties

severity
HIGH
score
8.1
cve_id
CVE-2026-82071
signal_observed_at
2026-09-16T21:37:08+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
published_at
2026-09-08T17:18:36.140
last_modified
2026-09-16T20:39:21.083

Related Entities (3)

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Write

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82071 — Ninja Signal Threat Intelligence | Ninja Signal