Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9742

Опубликовано: 09 июн. 2026
Источник: nvd
CVSS3: 7.5
CVSS3: 5.9
EPSS Низкий

Описание

When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in affected product configurations.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Версия от 8.2.0 (включая) до 8.2.10 (исключая)
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Версия от 8.3.0 (включая) до 8.3.3 (исключая)

EPSS

Процентиль: 27%
0.00347
Низкий

7.5 High

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-1287

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in affected product configurations.

CVSS3: 7.5
debian
около 2 месяцев назад

When OIDC authentication is enabled in configuration, clients may set ...

CVSS3: 7.5
github
около 2 месяцев назад

When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in affected product configurations.

EPSS

Процентиль: 27%
0.00347
Низкий

7.5 High

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-1287