CVE-2026-87109: MongoDB Ops Manager
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project.
Affected products
- MongoDB Ops Manager: from 7.0.0, up to and including 7.0.23; from 8.0.0, before 8.0.27 (fixed in 8.0.27)
Published 2026-10-09. Last modified 2026-10-09.