已认证为 Ops Manager 用户且拥有只读项目角色的用户,在具备相应记录标识符的情况下,可以获取与其他项目关联的每日主机监控记录。由于所有权验证不充分,可能导致部署元数据(包括主机和配置详情)泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | Ops Manager | 7.0.0 ~ 7.0.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87110 | 5.3 MEDIUM | Ops Manager Uncontrolled Resource Consumption in Monitoring Endpoints |
| CVE-2026-87109 | 5.3 MEDIUM | Ops Manager Sensitive MFA Enrollment Information Exposure in User Listings |
No comments yet