Thousands of MongoDB, Memcached and CouchDB Instances Found Exposed Online
A ZoomEye scan conducted on 22 September 2026 discovered 2,590 MongoDB, 1,469 Memcached, and 387 CouchDB instances publicly accessible on their default ports. MongoDB deployments from pre-3.0 versions often retain open configurations that allow unauthenticated access to all databases, enabling data theft, modification, and in some cases server-side code execution. Memcached lacks any built-in authentication by design, relying entirely on network isolation, meaning any publicly reachable instance exposes cached data such as session tokens and user objects. CouchDB's HTTP-based interface doubles as an administrative endpoint, and instances bound to all network interfaces with weak or absent credentials represent a full administrative compromise. Security guidance across all three services centres on restricting network exposure, enabling authentication where available, and auditing legacy deployments that predate modern secure defaults.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in