BIT-mongodb-2026-82057

    Dashboard / Vulnerabilities / BIT-mongodb-2026-82057

    BIT-mongodb-2026-82057

    Published: 17 Sept 2026Last Modified: 17 Sept 2026

    Summary: Type Confusion in MongoDB Server WiredTiger Storage Engine via Custom Collection Configuration Leads to Persistent Denial of Service

    Details: A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process. By specifying a custom WiredTiger storage configuration option with an incompatible value during collection creation, a user could cause a type confusion in the storage engine layer. When documents were subsequently read from the misconfigured collection, the resulting mismatch in expected data format led to corrupted memory interpretation and a server crash. The crafted collection configuration persists across restarts, requiring manual operator intervention to remediate.

    Affected packages

    Package

    Name: mongodb

    Purl: pkg:bitnami/mongodb

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 8.3.0
    Fixed -8.3.9

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-mongodb-2026-82057 | CVE-DB