← Vulnerability feed

Vulnerability record · CVE-2026-82052 · published 8 September 2026

CVE-2026-82052: Mongodb vulnerability

Mongodb · Mongodb

The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.

7.1 CVSS 4.0 High EPSS 0.50% · top 59.8% CWE-617 · CWE-617
7.1CVSS 4.0 base score
0.50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
16 Sep 2026Last modified by NVD

Description

The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jira.mongodb.org/browse/SERVER-127985 Issue TrackingVendor Advisory

Track CVE-2026-82052 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2025-14847MongoDB Server heap memory disclosure via compressed protocol headersMismatched length fields in Zlib-compressed protocol headers let an unauthenticated client trigger a read of uninitialized heap memory in MongoDB Ser…KEVEPSS 83%analysed9.8CVE-2025-3085Mongodb vulnerabilityA MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status…EPSS 0.27%9.8CVE-2024-8654Mongodb use of uninitialized resource vulnerabilityMongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation sta…EPSS 0.37%9.8CVE-2024-1351Mongodb improper certificate validation vulnerabilityUnder certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect…EPSS 0.50%9.2CVE-2026-82067Mongodb vulnerabilityImproper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in …EPSS 0.51%9.2CVE-2026-13072Mongodb heap-based buffer overflow vulnerabilityWhen compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro…EPSS 0.40%9.1CVE-2017-15535Mongodb vulnerabilityMongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol com…EPSS 1.6%9.0CVE-2026-18691Mongodb vulnerabilityAn issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechan…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2026-82052), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.