---
id: CVE-2026-87110
title: >-
  An unauthenticated user with network access to the Ops Manager web port can
  repeatedly request monitoring endpoints that perform costly work without rate
  limiting
summary: >-
  An unauthenticated user with network access to the Ops Manager web port can
  repeatedly request monitoring endpoints that perform costly work without rate
  limiting. This can temporarily slow other traffic served by the same process
  while …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-770
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T06:17:13.280'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87110'
references:
  - url: >-
      https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#ops-manager-server-8027
    label: cna@mongodb.com
tags:
  - nvd
ingestedAt: '2026-10-09T06:27:05.595Z'
---

## Overview

An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other traffic served by the same process while requests continue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
