Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-8053-MongoDB — Desc "CVE-2026-8053 CHECKER"-20260518-16h30-GMT+7 | Kitploit
Tools/GitHubGitHub/mgiay/cve-2026-8053-mongodb
Vulnerability ScannersVulnerability AnalysisConfiguration AuditingCloud SecurityDevSecOpsDatabase Security
GitHubmgiay/cve-2026-8053-mongodb

CVE-2026-8053-MongoDB

Desc "CVE-2026-8053 CHECKER"-20260518-16h30-GMT+7

View Repository
164 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-8053 — MongoDB Server Out-of-Bounds Write

Overview

AttributeValue
CVE IDCVE-2026-8053
Technical NameFlatBSON Duplicate Field Index Drift
Vulnerability TypeCWE-787 — Out-of-bounds Write
CVSS v4.08.7 (HIGH)
CVSS v3.18.8 (HIGH)
EPSS0.064% (20th percentile — low exploitation probability)
KEV (Known Exploited)Not recorded
Detection DateMongoDB Internal
Publication Date12/05/2026
Reserved Date06/05/2026
NVD StatusPUBLISHED / Awaiting Analysis

Detailed Description

Root Cause

The vulnerability exists in MongoDB Server's time-series collection system. Specifically, the error occurs due to:

An inconsistency in the mapping mechanism between field name and index inside the time-series bucket catalog.

When this mapping drifts, a write operation can cause an out-of-bounds write in the mongod process. Under certain conditions, this can escalate to Remote Code Execution.

Technical Context — FlatBSON & Time-Series Bucket Catalog

  • FlatBSON is an internal binary serialization format used by MongoDB, optimized over standard BSON for time-series operations.
  • Time-series bucket catalog is a data structure that manages "buckets" — each bucket contains multiple time-series data points grouped by time.
  • Inside this catalog, a mapping table (field-name → index) is maintained for fast field access. When this mapping suffers from duplicate or incorrect indexing (duplicate field index drift), subsequent write operations can write data outside the allocated memory range.

Exploitation Conditions

ConditionDescription
AuthenticationRequired — the attacker must have a valid MongoDB account
PrivilegesRequires write privilege to the database
User InteractionNone
NetworkExploitable remotely over network
ComplexityLow (attack complexity: LOW)

Affected Versions

MongoDB BranchAffected VersionsPatched Starting From
5.0< 5.0.33≥ 5.0.33
6.0< 6.0.28≥ 6.0.28
7.0< 7.0.34≥ 7.0.34
8.0< 8.0.23≥ 8.0.23
8.2< 8.2.9≥ 8.2.9
8.3< 8.3.2≥ 8.3.2

Note: Versions older than 5.0 (4.x, 3.x) are end-of-life (EOL). If you are running these versions, you must urgently upgrade to a supported branch.


Attack Vector (CVSS v4.0)```

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

| Thành phần | Giá trị | Ý nghĩa |
|------------|---------|---------|
| AV (Attack Vector) | **Network (N)** | Remote exploitation over network |
| AC (Attack Complexity) | **Low (L)** | No special conditions required |
| AT (Attack Requirements) | **None (N)** | No prerequisites required |
| PR (Privileges Required) | **Low (L)** | Only a user with write privileges needed |
| UI (User Interaction) | **None (N)** | No victim interaction required |
| VC/VI/VA (Vulnerable System) | **High / High / High** | Entire CIA triad affected |
| SC/SI/SA (Subsequent System) | **None** | No impact on other systems |

---

## Remediation Guide

### 1. Primary measure: Upgrade MongoDB Server

This is the **only and thorough** measure. Upgrade MongoDB Server to the corresponding patched version:```bash
# Kiểm tra phiên bản hiện tại
mongod --version

# Debian/Ubuntu — nâng cấp qua APT
sudo apt update
sudo apt install -y mongodb-org=<phiên-bản-đã-vá>

# RHEL/CentOS/Rocky — nâng cấp qua YUM/DNF
sudo yum update mongodb-org-<phiên-bản-đã-vá>

# Docker — pull image mới
docker pull mongo:<phiên-bản-đã-vá>

Specific patched versions for each branch:

BranchSample upgrade command (APT)
5.0sudo apt install -y mongodb-org=5.0.33
6.0sudo apt install -y mongodb-org=6.0.28
7.0sudo apt install -y mongodb-org=7.0.34
8.0sudo apt install -y mongodb-org=8.0.23
8.2sudo apt install -y mongodb-org=8.2.9
8.3sudo apt install -y mongodb-org=8.3.2

2. Temporary mitigation measures (if immediate upgrade is not possible)

  • Limit write permissions — Review and revoke unnecessary write permissions for database users: ```javascript // Kiểm tra user có quyền ghi vào time-series collections db.getUsers({ showCredentials: false });
  • Log monitoring — Monitor MongoDB logs to detect signs of anomalies: ```bash tail -f /var/log/mongodb/mongod.log | grep -iE "error|assert|abort|segfault"
  • Network segmentation — Restrict network access to the MongoDB port (default 27017), only allow from trusted IPs: ```bash

    Sử dụng firewall (iptables / nftables / firewalld)

    sudo ufw allow from to any port 27017
  • Enable authentication — Ensure MongoDB is configured with authorization: enabled in mongod.conf: ```yaml security: authorization: enabled
  • Temporarily disable time-series collections — If not using the time-series feature, consider disabling or not creating time-series collections until the patch is applied.

3. Verify after upgrade```bash

1. Xác nhận phiên bản mới

mongod --version

2. Kiểm tra trạng thái service

sudo systemctl status mongod

3. Kết nối và kiểm tra

mongosh --eval "db.version()"

4. Chạy script scan (đính kèm trong repo này)

sudo bash CVE-2026-8053-MongoDB-Fixed.sh

---

## Scanning Tool: `CVE-2026-8053-MongoDB-Fixed.sh`

Bash script that automatically scans and assesses whether a MongoDB Server is affected by CVE-2026-8053. The script is designed to run safely on **production** — all operations are **read-only**, no data is written to MongoDB.

### Key Features

| Feature | Description |
|---------|-------------|
| Installation detection | Automatically finds `mongod` binary path and shell (`mongosh`/`mongo`) |
| Version comparison | Checks installed version against the affected list (6 branches) |
| EOL detection | Alerts if MongoDB belongs to an end‑of‑life branch (4.4 and below) |
| Time‑series scan | Lists all time‑series collections across the entire cluster |
| Permission check | Lists users with write permissions — potential vulnerability exploit targets |
| Security check | Assesses `authorization`, `bindIp`, `TLS/SSL` configuration |
| Replica set support | Connects via connection string `mongodb://host:port/?replicaSet=name` |
| Multiple output modes | Normal (color), quiet (exit code), JSON (CI/CD) |
| Absolute safety | **0 write operations** — all MongoDB commands are read‑only |

### System Requirements

| Requirement | Detail |
|-------------|--------|
| Operating System | Linux (Ubuntu, Debian, RHEL, CentOS, Rocky, Alma, etc.) |
| Bash | ≥ 4.0 (supports associative arrays) |
| MongoDB Shell | `mongosh` (recommended) or `mongo` (legacy) |
| OS privileges | `sudo` / `root` (to read config file `/etc/mongod.conf`) |
| MongoDB privileges | User with read access to `system.users` and ability to run `listDatabases` |

### Command‑Line Options (CLI)
Download Tool