Improper Validation of Specified Type of Input in MongoDB Server - CVE-2026-9742
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of specified type of input in the authenticate command when processing the "mechanism" parameter. A remote attacker can send a specially crafted authenticate command to cause a denial of service.
Only configurations with OIDC authentication enabled are vulnerable.