Sceawere
Vulnerability Detail
CVE-2026-87108UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ops Manager Broken Access Control
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.1
- Creation Date
- 4h ago
- Vendor
- MongoDB
- Product
- Ops Manager
- Attack Type
- CWE-639: Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
An authenticated Ops Manager user with a read-only project role can retrieve a daily host monitoring record associated with a different project when they possess the required record identifier. Insufficient ownership validation can expose deployment metadata, including host and configuration details.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.1",
"pubDate": "2026-10-09T06:17:12.980Z",
"pubdate": "2026-10-09T06:17:12.980Z",
"executiveSummary": "This vulnerability is classified as an Improper Authorization (Broken Access Control) flaw within the Ops Manager monitoring subsystem.\nThe vulnerability allows an authenticated user assigned a read-only project role to bypass resource-level authorization boundaries.\nBy supplying a valid record identifier corresponding to a different project, the user can successfully retrieve daily host monitoring records that they are not authorized to view.\nThe primary impact is the unauthorized exposure of sensitive deployment metadata, which includes granular host-specific configuration details and operational telemetry.\nThe attack is limited to authenticated users, meaning an attacker must possess valid credentials within the Ops Manager ecosystem.\nThis represents a significant information disclosure risk, as internal architecture and configuration details can be weaponized by an attacker to facilitate further discovery or targetted exploitation within the infrastructure.\nThere are no requirements for specialized network positioning beyond standard authenticated access to the Ops Manager interface.",
"technicalDetails": "The root cause of this vulnerability lies in an insufficient ownership validation check within the monitoring data retrieval service of Ops Manager.\nWhen a user requests a daily host monitoring record, the application backend fails to verify that the requested resource identifier is cryptographically or logically scoped to the requester's project context.\nIn a secure implementation, the server-side logic must correlate the requester's identity and project authorization level with the ownership attribute of the requested monitoring record before returning the payload.\nIn the vulnerable state, the API endpoint relies on the client-provided record identifier without conducting an intermediate authorization check against the database or cache to ensure that the project ID associated with that record matches the user's current session scope.\nThe exploitation flow begins with a standard authentication sequence where the attacker obtains a valid session token as a user with a read-only project role.\nThe attacker then identifies valid target record identifiers, which may be discovered through enumeration, internal metadata leaks, or predictable pattern analysis of the API endpoints.\nOnce an identifier is obtained, the attacker transmits a request to the monitoring API endpoint with the foreign record ID.\nBecause the server lacks object-level authorization (OLA) or broken access control (BAC) enforcement, the application processes the request, retrieves the requested monitoring document, and transmits the JSON payload back to the attacker.\nThe payload returns sensitive host-level information, such as server configurations, hardware metadata, and deployment-specific operational parameters.\nThe lack of proper session-to-resource mapping allows for the leakage of cross-project data, undermining the integrity of the multi-tenant or multi-project separation implemented within Ops Manager.\nPost-exploitation, the gathered host configuration data can be leveraged to map internal network topologies or identify version-specific vulnerabilities in the underlying host stack, facilitating lateral movement or privilege escalation attempts within the host environment."
}