---
title: "CVE-2019-2386\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-2386?format=md
keywords: index, follow
---

# CVE-2019-2386

Publication date 6 August 2019

Last updated 18 February 2026

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.1 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2019-2386?format=md#impact-score)

Toggle side navigation

## Description

After user deletion in MongoDB Server the improper invalidation of
authorization sessions allows an authenticated user's session to persist
and become conflated with new accounts, if those accounts reuse the names
of deleted ones. This issue affects MongoDB Server v4.0 versions prior to
4.0.9; MongoDB Server v3.6 versions prior to 3.6.13 and MongoDB Server v3.4
versions prior to 3.4.22.
Workaround:
After deleting one or more users, restart any nodes which may have had
active user authorization sessions.
Refrain from creating user accounts with the same name as previously
deleted accounts.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2019-2386?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| mongodb | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 23.10 mantic | Not in release |
| 23.04 lunar | Not in release |
| 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Fixed 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.2 |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.04 LTS bionic | Fixed 1:3.6.3-0ubuntu1.3 |
| 16.04 LTS xenial | Vulnerable, fix deferred |
| 14.04 LTS trusty | Vulnerable, fix deferred |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2019-2386?format=md#patch-details)

## Notes

---

### [john-breton](https://launchpad.net/~john-breton)

The patch was released after the switch to SSPL upstream,
as such we cannot use it to patch Ubuntu releases.
The hope is a license-compliant third-party will make a
patch available in the future.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| mongodb | * Upstream:   [64d8e9e](https://github.com/mongodb/mongo/commit/64d8e9e1b12d16b54d6a592bae8110226c491b4e) * Upstream:   [db19e7c](https://github.com/mongodb/mongo/commit/db19e7ce84cfd702a4ba9983ee2ea5019f470f82) * Upstream:   [6dfb92b](https://github.com/mongodb/mongo/commit/6dfb92b1299de04677d0bd2230e89a52eb01003c) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.1 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | Low |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.1 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2386)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-2386)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-2386)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-2386)

### Related Ubuntu Security Notices (USN)

+ [USN-5052-1](https://usn.ubuntu.com/USN-5052-1)
+ MongoDB vulnerability
+ 26 August 2021

### Other references

* <https://jira.mongodb.org/browse/SERVER-38984>
* <https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0829>
* <https://www.cve.org/CVERecord?id=CVE-2019-2386>
