2590 MongoDB, 1469 Memcached and 387 CouchDB Results: Three Data Stores With Three Default Postures
Data stores are attractive targets because they hold the data directly, and because several of them have a history of shipping with authentication disabled. A ZoomEye query set collected on 22 September 2026 returned:
| Query | Total results |
|---|---|
port:27017 (MongoDB) |
2,590 |
port:11211 (Memcached) |
1,469 |
port:5984 (CouchDB) |
387 |
Each of these three services has a different default posture, and the difference explains both the counts and the remediation approach.
MongoDB: authentication was historically optional
MongoDB listens on 27017 by default. In versions before 3.0, the server accepted connections without authentication unless an administrator explicitly enabled it. Since 3.0, the default changed, but deployments upgraded from older versions or configured from older documentation frequently retained the open configuration.
A MongoDB instance that accepts unauthenticated connections exposes every database on the server. The impact is not limited to data theft: an unauthenticated administrative connection can also be used to modify data, create users, and in some configurations to execute server-side JavaScript.
The modern control is straightforward: enable authentication, bind to localhost or a management interface, and require TLS for any remote connection. The recurring problem is that the service was deployed before those defaults changed and nobody revisited it.
Memcached: no authentication by design
Memcached on 11211 is different. Memcached has no authentication mechanism in the base protocol. It is designed to be reached by application servers on a trusted network, and the security model is network isolation rather than credentials.
That design decision means a reachable Memcached instance is, by definition, an unauthenticated cache. The exposure has two consequences. The first is data disclosure: cached values frequently include session tokens, serialised user objects and rendered page fragments. The second is amplification: Memcached's UDP interface has been used as a reflection vector for large volumetric attacks, which is why UDP support was disabled by default in version 1.5.6.
The control is network placement. Memcached should not be reachable from outside the application network, and the UDP listener should be disabled unless there is a specific reason to enable it.
CouchDB: an HTTP API with an admin interface
CouchDB on 5984 is an HTTP-based document database. Its API is the same interface an administrator uses, which means a reachable CouchDB instance exposes an administrative HTTP endpoint.
CouchDB has had a well-documented history of administrative interface exposure, including the Fauxton web console. The relevant configuration is the bind address and the admin credentials. A CouchDB instance bound to all interfaces with a default or absent admin password is a full administrative compromise.
The count for CouchDB is the smallest of the three, which is consistent with a smaller installed base rather than with a better security posture.
Why the counts differ
The three counts reflect installed base and probe behaviour as much as they reflect security practice. MongoDB and Memcached are both widely deployed as components of larger applications, frequently on the same host as the application server. CouchDB has a smaller and more specialised user base.
A service that responds to a simple protocol probe is easier to index than one that requires a complete handshake. Memcached's text protocol responds to a trivial command, which makes it straightforward to identify. MongoDB's wire protocol is more structured but still identifiable.
What to check in your own estate
- Query your own netblocks for 27017, 11211 and 5984. Any result is a finding.
- Check the bind address. A service bound to 0.0.0.0 is reachable from every interface, including any public one.
- Check authentication state. For MongoDB, confirm authentication is enabled. For Memcached, confirm the network is isolated. For CouchDB, confirm the admin password is set and the bind address is restricted.
- Check the cloud security group or firewall rule. The rule that permits the traffic is often the actual root cause.
- Check for cached sensitive data. For Memcached, the contents matter as much as the reachability.
Limitations
These figures are a snapshot collected on 22 September 2026. A port that responds is a reachable service, not a confirmed unauthenticated one. Confirming that a MongoDB instance accepts unauthenticated connections requires an authentication attempt, which is a different measurement.
The counts are also not a complete inventory of exposed data stores. Services on non-default ports, services behind a proxy, and services that do not respond to a probe are not represented.
References
- ZoomEye, cyberspace search engine. Query set:
port:27017,port:11211,port:5984; collected 22 September 2026. - IANA, Service Name and Transport Protocol Port Number Registry.
- MongoDB, Security Checklist.
- Memcached, Security and access control documentation.
- Apache CouchDB, Security documentation.
Top comments (0)