Vulnerability Description
When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in affected product configurations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | >= 8.2.0, < 8.2.10 |
Related Weaknesses (CWE)
References
- https://jira.mongodb.org/browse/SERVER-124183PatchVendor AdvisoryIssue Tracking
FAQ
What is CVE-2026-9742?
CVE-2026-9742 is a vulnerability with a CVSS score of 7.5 (HIGH). When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is ...
How severe is CVE-2026-9742?
CVE-2026-9742 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-9742?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongodb.