Vulnerabilities in MongoDB
50 resultsVexday analysis
MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.
CVE-2026-14881HIGHCompass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flowEPSS 0.2%CVE-2026-13068LOWMongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege MisuseEPSS 0.1%CVE-2025-12100HIGHMongoDB BI Connector ODBC driver installation via MSI may leave ACLs unset on custom installation directoriesEPSS 0.1%CVE-2025-11575HIGHMongoDB Atlas SQL ODBC driver installation via MSI may leave ACLs unset on custom installation directoriesEPSS 0.1%CVE-2026-9735MEDIUMKeyfile contents are in MongoDB Server logsEPSS 0.1%CVE-2026-13062HIGHMongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded ClustersEPSS 0.1%CVE-2026-9751MEDIUMSensitive data could be written to mongod.logEPSS 0.1%CVE-2026-9741HIGHClient side encryption fails to encrypt values in a $vectorSearchEPSS 0.1%CVE-2026-13070MEDIUMImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process TerminationEPSS 0.1%CVE-2026-13067HIGHtlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain SocketEPSS 0.1%