CVE-2026-87108: MongoDB Ops Manager

Low severity, CVSS 3.1. EPSS: 0.1% chance of exploitation in the next 30 days.

An authenticated Ops Manager user with a read-only project role can retrieve a daily host monitoring record associated with a different project when they possess the required record identifier. Insufficient ownership validation can expose deployment metadata, including host and configuration details.

Affected products

  • MongoDB Ops Manager: from 7.0.0, up to and including 7.0.23; from 8.0.0, before 8.0.27 (fixed in 8.0.27)

Published 2026-10-09. Last modified 2026-10-09.