Sceawere

Vulnerability Detail

CVE-2026-103546UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MongoDB Kubernetes Controller Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1h ago
Vendor
MongoDB, Inc.
Product
Mongodb Controllers for Kubernetes
Attack Type
CWE-918 Server-Side request forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup configuration may allow a user who can modify an OpsManager custom resource to cause unintended administrative changes in Ops Manager. This affects deployments using Enterprise Ops Manager backup reconciliation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-05T22:16:56.520Z",
  "pubdate": "2026-10-05T22:16:56.520Z",
  "executiveSummary": "A vulnerability exists in MongoDB Controllers for Kubernetes concerning the insufficient validation of Ops Manager backup configurations.\nThe flaw stems from improper input sanitization within the reconciliation loop, which governs the synchronization between Kubernetes Custom Resources and the underlying Ops Manager application.\nAn authenticated user with permissions to modify an OpsManager custom resource can manipulate backup configuration parameters to trigger unintended administrative actions.\nThis vulnerability effectively grants unauthorized administrative control over the Ops Manager backup infrastructure, bypassing standard intended access controls.\nImpact includes the potential for unauthorized administrative configuration changes, which may lead to service disruption, data integrity risks, or escalated management privileges within the Ops Manager ecosystem.\nThe vulnerability specifically affects deployments utilizing Enterprise Ops Manager backup reconciliation capabilities.\nExploitation requires the attacker to possess sufficient Kubernetes-level privileges to modify the relevant Custom Resource Definitions (CRDs) within the cluster.",
  "technicalDetails": "The root cause of this vulnerability is an authorization and validation failure within the MongoDB Controller for Kubernetes reconciliation logic. When the controller processes an OpsManager Custom Resource (CR) to manage backup reconciliation, it fails to perform adequate server-side validation of the configuration inputs provided in the CR specification.\nIn the context of Kubernetes controllers, the reconciliation loop is responsible for observing the desired state defined in the CR and applying that state to the target infrastructure—in this case, the Enterprise Ops Manager. If the controller does not strictly enforce schema validation or sanitize configuration fields before pushing them to the Ops Manager API, it becomes susceptible to injection or configuration manipulation.\nThe attack flow begins with an authenticated user who holds RBAC permissions to modify the OpsManager custom resource within the Kubernetes cluster. By crafting a malicious or malformed backup configuration within the spec field of the OpsManager CR, the user can inject parameters that the controller inadvertently forwards to the Ops Manager administrative interface.\nBecause the controller operates with higher privileges than the end-user (acting as a service account with administrative rights over the Ops Manager instance), the controller effectively acts as a confused deputy. It blindly propagates the unauthorized parameters to the Ops Manager, which then executes the administrative action as requested by the manipulated configuration.\nThis vulnerability is particularly significant for Enterprise deployments where backup reconciliation is automated. If the controller does not distinguish between user-supplied backup settings and system-level administrative parameters, an attacker can influence settings that should be reserved for cluster administrators, such as altering storage configurations, modifying backup target destinations, or triggering administrative events that destabilize the backup state.\nAuthentication is required at the Kubernetes API level; the attacker must have the ability to update the specific OpsManager custom resource. The impact is strictly confined to the scope of Ops Manager administrative operations rather than direct host-level compromise, but the ability to impact backup configurations provides a high degree of control over the availability and recovery parameters of the database environment."
}
CVE-2026-103546: MongoDB Kubernetes Controller Authorization Bypass (MEDIUM Severity, CVSS: 4.3) | Sceawere