๐Ÿ” CVE Alert

CVE-2026-103546

MEDIUM 4.3

Improper validation of Ops Manager configuration in MongoDB Kubernetes Operator

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup configuration may allow a user who can modify an OpsManager custom resource to cause unintended administrative changes in Ops Manager. This affects deployments using Enterprise Ops Manager backup reconciliation.

CWE CWE-918
Vendor mongodb, inc.
Product mongodb controllers for kubernetes
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for mongodb, inc. mongodb controllers for kubernetes

Be the first to know when new medium vulnerabilities affecting mongodb, inc. mongodb controllers for kubernetes are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

MongoDB, Inc. / Mongodb Controllers for Kubernetes
0 < 1.13.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mongodb/mongodb-kubernetes/releases/tag/1.13.0