未经身份验证的用户,只要通过网络访问 Ops Manager 的 Web 端口,就可以反复请求执行高开销操作的监控端点,而服务器未对这些请求实施速率限制。这种攻击可能导致同一服务进程在处理这些请求期间,暂时减缓其他正常流量的响应速度。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | Ops Manager | 7.0.0 ~ 7.0.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87109 | 5.3 MEDIUM | Ops Manager Sensitive MFA Enrollment Information Exposure in User Listings |
| CVE-2026-87108 | 3.1 LOW | Ops Manager Improper Authorization in Daily Host Monitoring Retrieval |
No comments yet