CVE-2026-87109: CWE-201: Exposure of Sensitive Information Through Sent Data in MongoDB Ops Manager
Description
CVE-2026-87109 is a vulnerability in MongoDB Ops Manager that allows an authenticated organization member to access another member's pending authenticator enrollment seed if that enrollment is unconfirmed. This exposure occurs through user-listing endpoints and results in disclosure of secret authentication material within the same organization or project.
CVSS v4.0
Score 6.0medium
Affected software
MongoDB
Ops Manager
pkg:github/mongodb/ops-managerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-87109) in MongoDB Ops Manager involves an information exposure flaw (CWE-201) where an authenticated member of an Ops Manager organization can retrieve the pending authenticator enrollment seed of another member via user-listing endpoints while the target member's enrollment is still unconfirmed. The disclosed data is sensitive authentication material, potentially compromising the security of multi-factor authentication enrollment processes within the same organization or project.
Potential Impact
The impact is the unauthorized disclosure of secret authentication material (pending authenticator enrollment seeds) to other authenticated members within the same organization or project. This could undermine the security of the authentication process by exposing sensitive data that should remain confidential until enrollment confirmation.
Mitigation Recommendations
No explicit patch or remediation details are provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, organizations should consider limiting access to user-listing endpoints or restrict membership permissions to trusted users to reduce exposure risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mongodb
- Date Reserved
- 2026-09-08T20:29:22.918Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac883db2cdf04f656302138
Added to database: 10/09/2026, 06:04:11 UTC
Last enriched: 10/09/2026, 06:20:38 UTC
Last updated: 10/09/2026, 06:20:38 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.