CVE-2026-89099
Last modified
CVE-2026-89099 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Successful use of this issue may impact the confidentiality, integrity, and availability of the affected server process.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MongoDB | MongoDB Server | >= 8.3.0, < 8.3.11; >= 8.0, < 8.0.32; >= 7.0, < 7.0.43 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-89099?
How severe is CVE-2026-89099?
How do I fix CVE-2026-89099?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89089A SQL injection vulnerability exists in the JasperReports-ba…6.5
- CVE-2026-8909The WpMobi plugin for WordPress is vulnerable to Cross-Site …4.3
- CVE-2026-89090An unrecovered panic in the event stream header decoder in A…5.9
- CVE-2026-89092The nscd service in the GNU C Library 2.3.4 onwards may cras…4.2
- CVE-2026-89093The Better Messages – Chat Rooms, Group Chat, Private Messag…5.3
- CVE-2026-89094Forgejo before 16.0.4 allows remote code execution via a cra…9.9
- CVE-2026-8910The WP Emoticon Rating plugin for WordPress is vulnerable to…6.1
- CVE-2026-8911The WP AutoBuzz plugin for WordPress is vulnerable to Cross-…6.1
- CVE-2026-8912The Contest Gallery plugin for WordPress is vulnerable to SQ…7.5
- CVE-2026-8913A command Injection vulnerability exists in the WireGuard cl…8.5
- CVE-2026-89138The Filter Gallery plugin for WordPress is vulnerable to aut…4.3
- CVE-2026-89139Temporal Server compiles a Worker Controller Instance module…8.7
Are you affected by CVE-2026-89099?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
