CVE-2026-87110 PUBLISHED

Ops Manager Uncontrolled Resource Consumption in Monitoring Endpoints

Assigner: mongodb
Reserved: 08.09.2026 Published: 09.10.2026 Updated: 09.10.2026

An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other traffic served by the same process while requests continue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor MongoDB
Product Ops Manager
Versions Default: unaffected
  • affected from 7.0.0 to 7.0.23 (incl.)
  • affected from 8.0.0 to 8.0.27 (excl.)

References

Problem Types

  • CWE-770: Allocation of Resources Without Limits or Throttling CWE