CVE-2026-5170Disclosure(mongodb / mongodb)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during the limited and unpredictable window when the cluster is being promoted from a replica set to a sharded cluster. This may cause a denial of service by taking down the primary of the replica set. This issue affects MongoDB Server v8.2 versions prior to 8.2.2, MongoDB Server v8.0 versions between 8.0.18, MongoDB Server v7.0 versions between 7.0.31.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongodb

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-31)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
mongodb

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-30: 1Mentions · 2026-03-31: 2Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 203-3003-31
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-301
Disclosure1
2026-03-312
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5170 A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during the limited and unpredictable window when the c… https://www.cve.org/CVERecord?id=CVE-2026-5170

    Post summary

    The passage announces CVE-2026-5170, highlighting that users with constrained cluster privileges can cause a mongod crash within a narrow, unpredictable timeframe.

    00010199
    56.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5170 A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during the limited and unpredictable window when the c… https://www.cve.org/CVERecord?id=CVE-2026-5170 ----- Traducción: CVE-2026-5170 Un … http://infoflow.cloud`

    Post summary

    The text references CVE-2026-5170 as a crash vulnerability in MongoDB triggered by users with limited cluster privileges, but it does not provide evidence of a PoC, exploit, patch, or active exploitation.

    0000025
    65 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5170 - Users could trigger a crash of mongod primaries during promotion to sharded Intel Report: https://ift.tt/Vs7j4pB

    Post summary

    CVE-2026-5170 causes a crash of mongod primaries during sharding promotion, as reported in a threat alert.

    0000043
    280 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbmongodb---

Explore more