Vulnerabilities in MongoDB

162 results
Vexday analysis

MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.

CVE-2026-88026HIGHRegular expression injection via unescaped characters in LINQ query translation in MongoDB C# DriverEPSS 0.4%CVE-2026-13066HIGHServer-Side JavaScript DBPointer BSON Serialization Memory DisclosureEPSS 0.4%CVE-2026-13073MEDIUMMongoDB Aggregation Command Invariant Assertion Failure Leading to Process TerminationEPSS 0.4%CVE-2026-82059MEDIUMImproper Access Restriction of Internal Aggregation Expression in MongoDB Server Leads to Assertion Failure and Denial of ServiceEPSS 0.4%CVE-2026-82063MEDIUMUse-After-Free in MongoDB Server Cursor Management Component Leads to Denial of ServiceEPSS 0.4%CVE-2026-81533MEDIUMMongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT ValuesEPSS 0.4%CVE-2026-18705HIGHImproper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View DataEPSS 0.4%CVE-2026-18690HIGHImproper Authorization in MongoDB Server Allows Unauthorized Actions on System CollectionsEPSS 0.4%CVE-2026-18691CRITICALImproper Authentication in MongoDB Intra-Cluster Connections Allows Credential ExposureEPSS 0.4%CVE-2026-76797MEDIUMMongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated ReportsEPSS 0.4%CVE-2026-81526HIGHCross-database write redirection via unvalidated dotted database name in bulk write namespacesEPSS 0.3%CVE-2026-81521HIGHCross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go DriverEPSS 0.3%CVE-2026-13057MEDIUMAuthorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_METAEPSS 0.3%CVE-2026-18693HIGHOut-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory DisclosureEPSS 0.3%CVE-2026-13078MEDIUMLocal File Disclosure in MongoDB Server via MozJS Scripting Engine Module LoaderEPSS 0.3%CVE-2026-5170MEDIUMUsers could trigger a crash of mongod primaries during promotion to shardedEPSS 0.3%CVE-2026-82056MEDIUMRace Condition in MongoDB Server Text Index Query Parsing Leads to Heap Use-After-Free and Denial of ServiceEPSS 0.3%CVE-2026-84968MEDIUMHeap out-of-bounds read via corrupt nested BSON in field path error messageEPSS 0.3%CVE-2026-82073HIGHImproper Validation in MongoDB Server Aggregation Framework Allows Authorization Bypass and Unauthorized Collection Access with Atlas SearchEPSS 0.3%CVE-2026-82074HIGHIncorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection DataEPSS 0.3%