Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89099— Race Condition in MongoDB Server Document Value Layer Leads to Memory Corruption

Quick assessment

Affected
MongoDB MongoDB Server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MongoDB 服务器文档值层中的竞态条件(race condition)可能导致并发的服务器线程在没有同步机制的情况下对同一块内部内存进行操作,从而引发内存损坏。拥有数据库普通读写权限的认证用户可能通过常规客户端协议触发该条件,导致服务器终止,并可能引发进程内存的损坏,且损坏的内容可能受用户输入的影响。成功利用该问题可能影响受影响服务器进程的机密性、完整性和可用性。

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services

Affected Version Matrix 3

VendorProduct Version RangeStatus
MongoDB MongoDB Server 8.3.0< 8.3.11 affected
8.0< 8.0.32 affected
7.0< 7.0.43 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89099

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Race Condition in MongoDB Server Document Value Layer Leads to Memory Corruption
Source: CVE Program / CVE List V5
Vulnerability Description
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Successful use of this issue may impact the confidentiality, integrity, and availability of the affected server process.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB MongoDB Server 8.3.0 ~ 8.3.11 -

II. Public POCs for CVE-2026-89099

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89099

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-89099

No comments yet


Leave a comment