CVE-2026-87110: MongoDB Ops Manager
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other traffic served by the same process while requests continue.
Affected products
- MongoDB Ops Manager: from 7.0.0, up to and including 7.0.23; from 8.0.0, before 8.0.27 (fixed in 8.0.27)
Published 2026-10-09. Last modified 2026-10-09.