Vulnerabilities in MongoDB Inc

61 results
Vexday analysis

Com 61 CVEs catalogadas e nenhuma em exploração ativa no catálogo KEV da CISA, o MongoDB Inc apresenta uma taxa de exploração abaixo da média geral do catálogo, o que sugere superfície de risco operacional relativamente contida no momento. A ausência de falhas críticas, de provas de conceito públicas e de vulnerabilidades surgidas nos últimos 90 dias reforça um perfil de ameaça imediata baixo. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que historicamente favorece encadeamentos com outras vulnerabilidades e merece atenção contínua em revisões de código e configuração. A CVE mais relevante no momento, CVE-2023-0437, possui EPSS de 0,011, indicando baixa probabilidade estimada de exploração em curto prazo, embora seu monitoramento continue recomendado para equipes que mantêm ambientes MongoDB em produção.

CVE-2026-1848HIGHConnections received from the proxy port may not count towards total accepted connectionsEPSS 0.3%CVE-2025-10059MEDIUMMongoDB Server router will crash when incorrect lsid is set on a sharded queryEPSS 0.3%CVE-2025-3085HIGHMongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revokedEPSS 0.3%CVE-2024-7553HIGHAccessing Untrusted Directory May Allow Local Privilege EscalationEPSS 0.3%CVE-2026-1847HIGHMongoDB Server may crash when inserting large documentsEPSS 0.3%CVE-2026-1850HIGHAn authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplificationEPSS 0.3%CVE-2025-6706MEDIUMRunning certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB ServerEPSS 0.2%CVE-2025-6711MEDIUMIncomplete Redaction of Sensitive Information in MongoDB Server LogsEPSS 0.2%CVE-2026-4359LOWHeap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated bufferEPSS 0.2%CVE-2026-2303MEDIUMHeap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leakEPSS 0.2%CVE-2024-3371HIGHInsufficient validation of external input in Compass may enable MITM attacksEPSS 0.2%CVE-2025-1693LOWMongoDB Shell may be susceptible to control character Injection via shell outputEPSS 0.2%CVE-2024-8207MEDIUMMongoDB Server binaries may load potentially insecure shared libraries from specific relative pathsEPSS 0.2%CVE-2026-2302MEDIUMUnsafe Reflection in Mongoid::Criteria.from_hashEPSS 0.2%CVE-2025-3082LOWUser may override a view's collation and gain unauthorized access to underlying dataEPSS 0.2%CVE-2025-6707MEDIUMRace condition in privilege cache invalidation cycleEPSS 0.2%CVE-2025-1756HIGHMongoDB Shell may be susceptible to local privilege escalation in WindowsEPSS 0.2%CVE-2025-1755HIGHMongoDB Compass may be susceptible to local privilege escalation in WindowsEPSS 0.1%CVE-2025-11535HIGHMongoDB Connector for BI installation MSI leave ACLs unset on custom installation directoriesEPSS 0.1%CVE-2024-8013LOWCSFLE and Queryable Encryption self-lookup may fail to encrypt values in subpipelinesEPSS 0.1%