CVE Vulnerabilities

CVE-2026-25612

Unrestricted Externally Accessible Lock

Published: Feb 10, 2026 | Modified: Feb 10, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently collide with one another in this representation causing unavailability between them due to conflicting locks.

Weakness

The product properly checks for the existence of a lock, but the lock can be externally controlled or influenced by an actor that is outside of the intended sphere of control.

Affected Software

NameVendorStart VersionEnd Version
MongodbUbuntuupstream*

Potential Mitigations

References