Sceawere

Vulnerability Detail

CVE-2026-87110UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ops Manager Unauthenticated Resource Exhaustion

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
MongoDB
Product
Ops Manager
Attack Type
CWE-770: Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other traffic served by the same process while requests continue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-09T06:17:13.280Z",
  "pubdate": "2026-10-09T06:17:13.280Z",
  "executiveSummary": "This vulnerability involves a resource exhaustion condition in Ops Manager, categorized as a Denial of Service (DoS) risk. The issue stems from the lack of rate limiting on specific monitoring endpoints that execute resource-intensive operations.\nAn unauthenticated attacker with network access to the Ops Manager web interface can trigger these costly functions repeatedly. By flooding the application with requests, the attacker induces significant latency or total service degradation for other legitimate users sharing the same process space.\nThe vulnerability affects the core monitoring architecture of Ops Manager. Because the service does not enforce request throttling or authentication checks for these endpoints, it is susceptible to abuse by any actor capable of reaching the web port.\nThe risk implication is a potential disruption of monitoring services, which may result in delayed alerting or incomplete visibility into the managed infrastructure. The exploitation does not require advanced access, relying solely on the ability to transmit network traffic to the service port. There is no evidence of remote code execution or data exfiltration associated with this vulnerability, but the potential for availability impact remains significant in production environments where system responsiveness is critical.",
  "technicalDetails": "The vulnerability originates in the application logic responsible for processing monitoring-related HTTP requests. The Ops Manager web server exposes various endpoints that facilitate data retrieval and diagnostic reporting. Several of these endpoints initiate complex, synchronous backend operations that consume substantial CPU and memory resources to compute or retrieve the requested monitoring metrics.\nThe root cause is the absence of an integrated rate-limiting mechanism or request queuing policy for these high-cost endpoints. Furthermore, these endpoints do not mandate authentication, allowing unauthenticated entities to invoke heavy processing cycles without restriction. Because the web server process manages these requests concurrently or in a shared thread pool, an attacker can intentionally saturate the service by generating a high volume of concurrent or sequential requests.\nThe attack flow proceeds as follows: First, the attacker identifies the target monitoring endpoints accessible over the network on the Ops Manager web port. Second, the attacker executes a script or tool to dispatch a sustained stream of HTTP requests to these specific endpoints. Third, the Ops Manager process begins executing the resource-intensive tasks associated with each incoming request. As the workload accumulates, the process reaches capacity limits, causing queuing delays and increasing response latency for all concurrent requests, including those from authorized monitoring agents or administrative users.\nThe impact of this exploitation is a Denial of Service (DoS) state. While the system remains technically 'running,' the performance degradation effectively renders the monitoring functionality unusable for the duration of the attack. Since the operations are performed on the same process handling standard traffic, the impact can extend to other web-accessible management features provided by the Ops Manager instance. Post-exploitation impact is limited to availability; the attacker does not gain unauthorized data access or system persistence via this vector. The vulnerability persists as long as the cost of the requested operation remains disproportionately higher than the cost of the request generation, and while no guardrails exist to prevent rapid-fire invocation of these functions by anonymous network actors."
}
CVE-2026-87110: Ops Manager Unauthenticated Resource Exhaustion (MEDIUM Severity, CVSS: 5.3) | Sceawere