Vulnerabilidades em MongoDB
155 resultadosAnálise Vexday
MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.
CVE-2026-9747HIGHCrafted cross-shard merge aggregation crashes MongoDB ServerEPSS 0.3%CVE-2026-9752HIGHGeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generationEPSS 0.3%CVE-2026-18711HIGHUse-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory DisclosureEPSS 0.3%CVE-2026-9746HIGHServer crashes in case of the use of exchangeEPSS 0.3%CVE-2026-9749HIGHUsing MaxKey() may crash the serverEPSS 0.3%CVE-2026-13057MEDIUMAuthorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_METAEPSS 0.3%CVE-2026-81522HIGHCross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ DriverEPSS 0.3%CVE-2026-18705HIGHImproper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View DataEPSS 0.3%CVE-2026-88036MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C DriverEPSS 0.3%CVE-2026-75159HIGHMongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Cause Process TerminationEPSS 0.3%CVE-2026-81517HIGHMongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of SQL ServiceEPSS 0.3%CVE-2026-88031MEDIUMGridFS data deletion via query-operator injection in file IDs in the MongoDB Go DriverEPSS 0.3%CVE-2026-88030MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Ruby DriverEPSS 0.3%CVE-2026-88029MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Python DriverEPSS 0.3%CVE-2026-82059MEDIUMImproper Access Restriction of Internal Aggregation Expression in MongoDB Server Leads to Assertion Failure and Denial of ServiceEPSS 0.3%CVE-2026-82063MEDIUMUse-After-Free in MongoDB Server Cursor Management Component Leads to Denial of ServiceEPSS 0.3%CVE-2026-18707MEDIUMImproper Input Validation in MongoDB Aggregation Command Handling Leads to Denial of ServiceEPSS 0.3%CVE-2026-6914HIGHMD5 checksum creation may cause availability lossEPSS 0.3%CVE-2026-88033MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Java DriverEPSS 0.3%CVE-2026-88034MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C++ DriverEPSS 0.3%