A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-9740

CVE-2026-9740: MongoDB Server DoS Vulnerability

CVE-2026-9740 is a denial-of-service flaw in MongoDB Server's BSON validation logic that lets unauthenticated attackers crash the mongod process. This article covers technical details, affected versions, and mitigation.

Published: June 11, 2026

CVE-2026-9740 Overview

CVE-2026-9740 is a denial-of-service vulnerability in MongoDB Server's BSON validation logic. An unauthenticated remote attacker can crash the mongod process by sending a specially crafted message. The flaw resides in how the BSON validator handles nested binary data structures, where mutual recursion between validation functions resets internal depth tracking. This allows uncontrolled recursion that exhausts the call stack and terminates the database process. The issue is classified under CWE-674: Uncontrolled Recursion.

Critical Impact

Unauthenticated network attackers can repeatedly crash MongoDB Server instances, causing service outages and database availability loss.

Affected Products

  • MongoDB Server (see MongoDB Server Issue Tracking for affected versions)

Discovery Timeline

  • 2026-06-09 - CVE-2026-9740 published to NVD
  • 2026-06-10 - Last updated in NVD database

Technical Details for CVE-2026-9740

Vulnerability Analysis

The vulnerability exists in the BSON (Binary JSON) validation routines used by MongoDB Server to verify incoming wire protocol messages. When the validator encounters nested binary data structures, it transfers control between multiple validation functions through mutual recursion. Each re-entry into a paired validation function resets the depth counter that is intended to prevent runaway recursion.

An attacker who crafts a BSON payload with sufficiently deep nesting of binary subtype fields can drive the validator into unbounded recursion. The recursion consumes the thread stack until the operating system terminates the mongod process. Because validation occurs before authentication completes, no credentials are required to trigger the crash.

Root Cause

The root cause is improper depth tracking across mutually recursive validation functions. A single depth counter scoped to one function does not account for control transfers into a peer validator. Each cross-function call effectively starts a fresh depth measurement while the actual call stack continues to grow. This pattern matches CWE-674: Uncontrolled Recursion.

Attack Vector

Attackers exploit this flaw over the network by connecting to any exposed MongoDB listener and sending a malformed BSON document. The attack requires no authentication and no user interaction. A single crafted message is sufficient to terminate the process, and repeated messages produce a sustained denial of service against the database tier.

No verified proof-of-concept code has been published. See the MongoDB Server Issue Tracking entry for additional technical context.

Detection Methods for CVE-2026-9740

Indicators of Compromise

  • Unexpected mongod process termination or repeated automatic restarts under supervisor control such as systemd or Kubernetes
  • Stack overflow or SIGSEGV entries correlated with BSON parsing in MongoDB logs immediately before crash
  • Spikes in inbound connections to MongoDB ports (default 27017) followed by abrupt session resets

Detection Strategies

  • Monitor MongoDB server logs for abnormal termination signatures and assertion failures originating from BSON validation code paths
  • Inspect wire protocol traffic for BSON messages containing deeply nested binary subtype elements that exceed normal application depth
  • Correlate connection patterns from unauthenticated sources with subsequent process restarts to identify exploitation attempts

Monitoring Recommendations

  • Alert on mongod process uptime resets and crash loops across replica set members
  • Track replica set elections and primary step-downs that occur without operator action, as these can indicate node-level crashes
  • Enable network telemetry on database-tier subnets to capture source IPs sending malformed wire protocol messages

How to Mitigate CVE-2026-9740

Immediate Actions Required

  • Restrict network access to MongoDB listeners using firewall rules so only trusted application hosts can reach port 27017
  • Apply the fixed MongoDB Server release referenced in the MongoDB Server Issue Tracking advisory as soon as it is available for your deployment channel
  • Audit MongoDB deployments for instances exposed to the public internet and remove direct exposure

Patch Information

Refer to the official MongoDB Server Issue Tracking entry for affected version ranges and fixed builds. Upgrade all replica set members and sharded cluster components to the patched release using a rolling restart to preserve availability during remediation.

Workarounds

  • Place MongoDB instances behind a network policy or VPC security group that allows only application-tier source addresses
  • Require TLS client authentication on MongoDB listeners to filter unauthenticated connection attempts at the transport layer
  • Run mongod under a process supervisor configured for fast automatic restart to reduce outage duration if exploitation occurs
bash
# Example iptables rule restricting MongoDB to a trusted application subnet
iptables -A INPUT -p tcp --dport 27017 -s 10.0.10.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 27017 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechMongodb

  • SeverityHIGH

  • CVSS Score8.7

  • EPSS Probability0.03%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-674
  • Technical References
  • MongoDB Server Issue Tracking
  • Related CVEs
  • CVE-2026-9748: MongoDB PauseExecution DoS Vulnerability

  • CVE-2026-9747: MongoDB Server DoS Vulnerability

  • CVE-2026-9743: MongoDB Server 8.0 DoS Vulnerability

  • CVE-2026-9750: MongoDB Server DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English