An authenticated Ops Manager user with a read-only project role can retrieve a daily host monitoring record associated with a different project when they possess the required record identifier. Insufficient ownership validation can expose deployment metadata, including host and configuration details.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 09 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb ops Manager
Vendors & Products Mongodb
Mongodb ops Manager

Fri, 09 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
Description An authenticated Ops Manager user with a read-only project role can retrieve a daily host monitoring record associated with a different project when they possess the required record identifier. Insufficient ownership validation can expose deployment metadata, including host and configuration details.
Title Ops Manager Improper Authorization in Daily Host Monitoring Retrieval
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-09T05:54:58.769Z

Reserved: 2026-09-08T20:27:56.733Z

Link: CVE-2026-87108

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T06:17:12.980

Modified: 2026-10-09T06:17:12.980

Link: CVE-2026-87108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T07:30:17Z

Weaknesses