Back

HIGH

Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members

Published Sep 8, 2026

Description

A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authentication, and the assertion's assumptions about internal state do not hold for all member configurations, causing the server process to terminate.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mongodb
Published Sep 8, 2026
Updated Sep 8, 2026
Reserved Aug 27, 2026
CISA Vulnrichment
Updated Sep 8, 2026
NVD
Status Analyzed
Modified Sep 16, 2026
Red Hat
Severity n/a
Public date n/a