
Desc "CVE-2026-8053 CHECKER"-20260518-16h30-GMT+7
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-8053 |
| Technical Name | FlatBSON Duplicate Field Index Drift |
| Vulnerability Type | CWE-787 — Out-of-bounds Write |
| CVSS v4.0 | 8.7 (HIGH) |
| CVSS v3.1 | 8.8 (HIGH) |
| EPSS | 0.064% (20th percentile — low exploitation probability) |
| KEV (Known Exploited) | Not recorded |
| Detection Date | MongoDB Internal |
| Publication Date | 12/05/2026 |
| Reserved Date | 06/05/2026 |
| NVD Status | PUBLISHED / Awaiting Analysis |
The vulnerability exists in MongoDB Server's time-series collection system. Specifically, the error occurs due to:
An inconsistency in the mapping mechanism between field name and index inside the time-series bucket catalog.
When this mapping drifts, a write operation can cause an out-of-bounds write in the mongod process. Under certain conditions, this can escalate to Remote Code Execution.
| Condition | Description |
|---|---|
| Authentication | Required — the attacker must have a valid MongoDB account |
| Privileges | Requires write privilege to the database |
| User Interaction | None |
| Network | Exploitable remotely over network |
| Complexity | Low (attack complexity: LOW) |
| MongoDB Branch | Affected Versions | Patched Starting From |
|---|---|---|
| 5.0 | < 5.0.33 | ≥ 5.0.33 |
| 6.0 | < 6.0.28 | ≥ 6.0.28 |
| 7.0 | < 7.0.34 | ≥ 7.0.34 |
| 8.0 | < 8.0.23 | ≥ 8.0.23 |
| 8.2 | < 8.2.9 | ≥ 8.2.9 |
| 8.3 | < 8.3.2 | ≥ 8.3.2 |
Note: Versions older than 5.0 (4.x, 3.x) are end-of-life (EOL). If you are running these versions, you must urgently upgrade to a supported branch.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
| Thành phần | Giá trị | Ý nghĩa |
|------------|---------|---------|
| AV (Attack Vector) | **Network (N)** | Remote exploitation over network |
| AC (Attack Complexity) | **Low (L)** | No special conditions required |
| AT (Attack Requirements) | **None (N)** | No prerequisites required |
| PR (Privileges Required) | **Low (L)** | Only a user with write privileges needed |
| UI (User Interaction) | **None (N)** | No victim interaction required |
| VC/VI/VA (Vulnerable System) | **High / High / High** | Entire CIA triad affected |
| SC/SI/SA (Subsequent System) | **None** | No impact on other systems |
---
## Remediation Guide
### 1. Primary measure: Upgrade MongoDB Server
This is the **only and thorough** measure. Upgrade MongoDB Server to the corresponding patched version:```bash
# Kiểm tra phiên bản hiện tại
mongod --version
# Debian/Ubuntu — nâng cấp qua APT
sudo apt update
sudo apt install -y mongodb-org=<phiên-bản-đã-vá>
# RHEL/CentOS/Rocky — nâng cấp qua YUM/DNF
sudo yum update mongodb-org-<phiên-bản-đã-vá>
# Docker — pull image mới
docker pull mongo:<phiên-bản-đã-vá>
Specific patched versions for each branch:
| Branch | Sample upgrade command (APT) |
|---|---|
| 5.0 | sudo apt install -y mongodb-org=5.0.33 |
| 6.0 | sudo apt install -y mongodb-org=6.0.28 |
| 7.0 | sudo apt install -y mongodb-org=7.0.34 |
| 8.0 | sudo apt install -y mongodb-org=8.0.23 |
| 8.2 | sudo apt install -y mongodb-org=8.2.9 |
| 8.3 | sudo apt install -y mongodb-org=8.3.2 |
authorization: enabled in mongod.conf: ```yaml
security:
authorization: enabled
mongod --version
sudo systemctl status mongod
mongosh --eval "db.version()"
sudo bash CVE-2026-8053-MongoDB-Fixed.sh
---
## Scanning Tool: `CVE-2026-8053-MongoDB-Fixed.sh`
Bash script that automatically scans and assesses whether a MongoDB Server is affected by CVE-2026-8053. The script is designed to run safely on **production** — all operations are **read-only**, no data is written to MongoDB.
### Key Features
| Feature | Description |
|---------|-------------|
| Installation detection | Automatically finds `mongod` binary path and shell (`mongosh`/`mongo`) |
| Version comparison | Checks installed version against the affected list (6 branches) |
| EOL detection | Alerts if MongoDB belongs to an end‑of‑life branch (4.4 and below) |
| Time‑series scan | Lists all time‑series collections across the entire cluster |
| Permission check | Lists users with write permissions — potential vulnerability exploit targets |
| Security check | Assesses `authorization`, `bindIp`, `TLS/SSL` configuration |
| Replica set support | Connects via connection string `mongodb://host:port/?replicaSet=name` |
| Multiple output modes | Normal (color), quiet (exit code), JSON (CI/CD) |
| Absolute safety | **0 write operations** — all MongoDB commands are read‑only |
### System Requirements
| Requirement | Detail |
|-------------|--------|
| Operating System | Linux (Ubuntu, Debian, RHEL, CentOS, Rocky, Alma, etc.) |
| Bash | ≥ 4.0 (supports associative arrays) |
| MongoDB Shell | `mongosh` (recommended) or `mongo` (legacy) |
| OS privileges | `sudo` / `root` (to read config file `/etc/mongod.conf`) |
| MongoDB privileges | User with read access to `system.users` and ability to run `listDatabases` |
### Command‑Line Options (CLI)