Vulnerabilidades en MONGODB
162 resultadosAnálisis Vexday
MongoDB apresenta um perfil de risco mínimo com apenas 1 CVE crítica registrada na base, sem evidência atual de exploração em ataques documentados. A vulnerabilidade não é recente e está associada à fraqueza CWE-1104 (Use of Unmaintained Third Party Components), indicando risco potencial relacionado a dependências obsoletas em vez de falhas diretas do produto.
CVE-2026-84962MEDIUMAuthenticated KMS request forgery via CRLF injection in GCP key identifier stringsEPSS 0.2%CVE-2025-11695HIGHConfiguration may unexpectedly disable certificate validationEPSS 0.2%CVE-2026-9735MEDIUMKeyfile contents are in MongoDB Server logsEPSS 0.2%CVE-2026-18712HIGHImproper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other CollectionsEPSS 0.2%CVE-2025-12100HIGHMongoDB BI Connector ODBC driver installation via MSI may leave ACLs unset on custom installation directoriesEPSS 0.2%CVE-2026-9741HIGHClient side encryption fails to encrypt values in a $vectorSearchEPSS 0.2%CVE-2026-9751MEDIUMSensitive data could be written to mongod.logEPSS 0.2%CVE-2026-18710HIGHCleartext Storage of Sensitive Information in MongoDB Driver Logging During Client InitializationEPSS 0.1%CVE-2026-18703LOWImproper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication MethodEPSS 0.1%CVE-2026-84966MEDIUMBSON element injection via NUL-embedded document keys in builder appendEPSS 0.1%CVE-2026-88035MEDIUMHeap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C DriverEPSS 0.1%CVE-2025-11575HIGHMongoDB Atlas SQL ODBC driver installation via MSI may leave ACLs unset on custom installation directoriesEPSS 0.1%CVE-2026-13070MEDIUMImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process TerminationEPSS 0.1%CVE-2026-96749HIGHHeap out-of-bounds write via signed size overflow in BSON document encodingEPSS 0.1%CVE-2026-96747MEDIUMForced local Unix socket connection via dot-sock KMS endpoint in client-side field encryptionEPSS 0.1%CVE-2026-84965MEDIUMHeap write primitive via size round-up wrap during JSON parsing on 32-bit buildsEPSS 0.1%CVE-2026-84970MEDIUMHeap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parserEPSS 0.1%CVE-2026-19502MEDIUMInsufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLIEPSS 0.1%CVE-2026-75573MEDIUMMongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Are SuppliedEPSS 0.1%CVE-2026-81523LOWCross-tenant database retargeting via dot/NUL injection in namespace strings in libmongocryptEPSS 0.1%