PT-2026-48290 · Mongodb · Mongodb Server

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2026-9742

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in affected product configurations.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-9742

Affected Products

Mongodb Server