Vulnerabilities in MongoDB
162 resultsVexday analysis
MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.
CVE-2026-82070HIGHInsufficiently Protected Credentials in MongoDB Server Diagnostic Reporting InterfaceEPSS 0.3%CVE-2026-82074HIGHIncorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection DataEPSS 0.3%CVE-2025-14911HIGHInteger Overflow in GridFS chunkSize Leading to Heap Allocation FailureEPSS 0.3%CVE-2026-82060LOWInsufficient Validation of Shard Key Values in MongoDB Server Leads to Query Operator Injection in Change Stream Post-Image LookupsEPSS 0.3%CVE-2026-18888HIGHMongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character dataEPSS 0.3%CVE-2026-89099HIGHRace Condition in MongoDB Server Document Value Layer Leads to Memory CorruptionEPSS 0.3%CVE-2026-84963MEDIUMSilent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parserEPSS 0.3%CVE-2026-81527MEDIUMNoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translationEPSS 0.3%CVE-2026-77184MEDIUMMongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE OutputEPSS 0.3%CVE-2026-96745MEDIUMPHP object injection via unsuppressible __pclass class inference in command monitoring eventsEPSS 0.3%CVE-2026-13069HIGHQueryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource ExhaustionEPSS 0.3%CVE-2026-76798MEDIUMMongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML ReportsEPSS 0.3%CVE-2026-96744HIGHUnauthorized cache lock takeover via expression injection in lock owner values in MongoDB integration for LaravelEPSS 0.3%CVE-2026-6915MEDIUMFlaw in the updateUser Command May Allow Unauthorized Configuration ChangeEPSS 0.3%CVE-2026-75159HIGHMongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Cause Process TerminationEPSS 0.3%CVE-2026-81529HIGHConnection-option injection via unescaped settings in the canonical MongoDB URL builderEPSS 0.3%CVE-2026-13061MEDIUMImproper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation StageEPSS 0.3%CVE-2026-18702MEDIUMImproper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic SettingsEPSS 0.3%CVE-2026-81528MEDIUMNoSQL injection via array replacement bypassing update shape validation in driver write pathEPSS 0.3%CVE-2026-84969MEDIUMHeap overflow via truncated base64 encoding of binary fields in length-limited JSON outputEPSS 0.3%