Sceawere

Vulnerability Detail

CVE-2026-87109UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ops Manager Unauthorized Secret Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
MongoDB
Product
Ops Manager
Attack Type
CWE-201: Exposure of Sensitive Information Through Sent Data
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-09T06:17:13.140Z",
  "pubdate": "2026-10-09T06:17:13.140Z",
  "executiveSummary": "This vulnerability is an improper access control flaw within the Ops Manager user-listing functionality. It allows an authenticated member of an organization to access sensitive, unencrypted authenticator enrollment seeds belonging to other members who have initiated but not yet completed the Multi-Factor Authentication (MFA) setup process.\nThe vulnerability type is categorized as Improper Authorization, leading to the unauthorized disclosure of sensitive authentication material. The impact is significant, as exposure of an enrollment seed enables an attacker to derive the Time-based One-Time Password (TOTP) codes for the victim's account.\nThe affected system is the Ops Manager platform. The risk implications are critical, as this allows for full account takeover (ATO) if the attacker uses the seed to authenticate as the victim. Exploitation requires the attacker to be an authenticated member within the same organization or project. No special privileges beyond standard membership are necessary, and the attack is highly reliable during the window where the victim's enrollment state remains 'unconfirmed'.\nOrganizations using Ops Manager must treat MFA enrollment processes as sensitive transactions and ensure that associated metadata is isolated to the specific user context, preventing cross-user information leakage during the pendency of the registration state.",
  "technicalDetails": "The vulnerability resides within the user-management API endpoints of the Ops Manager platform, specifically those responsible for retrieving lists of organization or project members. The root cause is an insecure object-level authorization (IDOR) or logic error in the backend response serialization process, where the API prematurely includes the secret enrollment seed in the user-object response payload before the MFA process is confirmed.\nUnder normal conditions, an authenticator enrollment seed (used for generating TOTP tokens) should be ephemeral, scoped strictly to the authenticated user's session, and never exposed to secondary users or administrative API calls that do not require explicit disclosure of secret material. In the identified vulnerability, the application logic fails to filter these sensitive fields when the member's enrollment state is marked as 'unconfirmed'.\nThe exploitation flow is as follows: 1. An attacker, possessing standard authenticated access to an Ops Manager organization, monitors the user-listing endpoints. 2. The attacker identifies a target member who has initiated an MFA setup but has not yet scanned the QR code or confirmed the token validity. 3. The attacker performs a GET request against the user-management endpoint (e.g., /api/public/v1.0/orgs/{ORG-ID}/members). 4. The API response returns an object representing the victim user, which contains the 'pending_enrollment_seed' or equivalent field. 5. The attacker parses this seed, imports it into a TOTP client (such as Google Authenticator or an automated script), and generates valid authentication codes.\nBy obtaining the secret seed, the attacker effectively bypasses the integrity of the MFA mechanism. Because the seed is the static secret shared between the server and the authenticator app, the attacker can generate valid codes indefinitely, assuming the victim completes the enrollment or the attacker uses the seed to preemptively finalize the setup if the backend logic permits. The vulnerability persists as long as the victim's enrollment status remains in a 'pending' state, and the API remains configured to serialize the secret into the response object. This exposure is exacerbated by the lack of field-level access control on the API, which fails to distinguish between data intended for the account owner and data intended for administrative viewing."
}
CVE-2026-87109: Ops Manager Unauthorized Secret Disclosure (MEDIUM Severity, CVSS: 5.3) | Sceawere