CVE-2026-82060: CWE-943: Improper Neutralization of Special Elements in Data Query Logic in MongoDB MongoDB Server
In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key values in sharded collections. When change stream events for such documents were processed with the updateLookup full document mode, the crafted values were embedded into internal post-image lookup queries without proper sanitization, causing them to be interpreted as query operators rather than literal equality values. This could result in change stream consumers receiving incorrect post-image documents or encountering non-resumable fatal errors.
AI Analysis
Technical Summary
This vulnerability involves improper neutralization of special elements in data query logic (CWE-943) in MongoDB Server. Authenticated users can insert documents with specially crafted shard key values that resemble query operators. When change streams process these documents with updateLookup mode, the crafted values are embedded into internal queries without proper sanitization, causing them to be interpreted as operators rather than literal values. This can result in incorrect post-image documents being delivered to change stream consumers or non-resumable fatal errors occurring.
Potential Impact
The impact is limited to change stream consumers who may receive incorrect post-image documents or encounter fatal errors that prevent resuming the change stream. There is no indication of privilege escalation, data leakage, or remote code execution. The CVSS score of 2.3 reflects a low severity with limited impact and requiring privileges to exploit.
Mitigation Recommendations
No official patch or remediation level is currently provided by the vendor. Patch status is not yet confirmed — check the MongoDB vendor advisory for current remediation guidance. Until a fix is available, users should be cautious when using change streams with updateLookup mode on sharded collections and consider restricting authenticated user permissions to prevent insertion of crafted shard key values.
CVE-2026-82060: CWE-943: Improper Neutralization of Special Elements in Data Query Logic in MongoDB MongoDB Server
Description
In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key values in sharded collections. When change stream events for such documents were processed with the updateLookup full document mode, the crafted values were embedded into internal post-image lookup queries without proper sanitization, causing them to be interpreted as query operators rather than literal equality values. This could result in change stream consumers receiving incorrect post-image documents or encountering non-resumable fatal errors.
CVSS v4.0
Score 2.3low
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper neutralization of special elements in data query logic (CWE-943) in MongoDB Server. Authenticated users can insert documents with specially crafted shard key values that resemble query operators. When change streams process these documents with updateLookup mode, the crafted values are embedded into internal queries without proper sanitization, causing them to be interpreted as operators rather than literal values. This can result in incorrect post-image documents being delivered to change stream consumers or non-resumable fatal errors occurring.
Potential Impact
The impact is limited to change stream consumers who may receive incorrect post-image documents or encounter fatal errors that prevent resuming the change stream. There is no indication of privilege escalation, data leakage, or remote code execution. The CVSS score of 2.3 reflects a low severity with limited impact and requiring privileges to exploit.
Mitigation Recommendations
No official patch or remediation level is currently provided by the vendor. Patch status is not yet confirmed — check the MongoDB vendor advisory for current remediation guidance. Until a fix is available, users should be cautious when using change streams with updateLookup mode on sharded collections and consider restricting authenticated user permissions to prevent insertion of crafted shard key values.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mongodb
- Date Reserved
- 2026-08-27T22:51:49.544Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa03a25acd9273b49ec3633
Added to database: 09/08/2026, 16:39:01 UTC
Last enriched: 09/08/2026, 16:53:14 UTC
Last updated: 09/09/2026, 00:23:00 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.