MongoDB announced patches for 24 server vulnerabilities.
One critical issue, CVE-2026-82067, allows unauthenticated users to gain full administrative access. This vulnerability carries a 9.2 severity rating. The flaw disables authorization systems during startup due to improper case-sensitivity handling.
The security updates apply to MongoDB server versions 7.0, 8.0, and 8.3. Other high-severity flaws addressed could enable denial-of-service attacks through resource exhaustion.
The company confirmed no known exploits of these vulnerabilities currently exist in the wild. This disclosure comes ahead of MongoDB's scheduled appearance at the Goldman Sachs Communacopia + Technology Conference.