已认证的 Ops Manager 组织成员可以通过用户列表接口,在另一成员身份验证器注册未确认期间,获取该成员的待处理身份验证器注册种子。这会导致同一组织或项目中的其他成员泄露秘密认证信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | Ops Manager | 7.0.0 ~ 7.0.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87110 | 5.3 MEDIUM | Ops Manager Uncontrolled Resource Consumption in Monitoring Endpoints |
| CVE-2026-87108 | 3.1 LOW | Ops Manager Improper Authorization in Daily Host Monitoring Retrieval |
No comments yet