When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in affected product configurations.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-124183 | Patch Vendor Advisory Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
23 Jul 2026, 09:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
18 Jun 2026, 14:34
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mongodb mongodb
Mongodb |
|
| CPE | cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:* | |
| References | () https://jira.mongodb.org/browse/SERVER-124183 - Patch, Vendor Advisory, Issue Tracking |
09 Jun 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 23:17
Updated : 2026-07-23 09:10
NVD link : CVE-2026-9742
Mitre link : CVE-2026-9742
CVE.ORG link : CVE-2026-9742
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-1287
Improper Validation of Specified Type of Input
