Vulnerabilidades em MongoDB
162 resultadosAnálise Vexday
MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.
CVE-2026-84967MEDIUMArbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminalEPSS 0.3%CVE-2026-81524MEDIUMCross-tenant database retargeting via dot/NUL injection in namespace strings in the C DriverEPSS 0.3%CVE-2026-84971HIGHPersistent client crash loop via undersized FLE2 insert-update ciphertext in decryption pathEPSS 0.3%CVE-2026-84964HIGHHeap corruption via OCSP request double free from crafted multi-URL certificate in TLS clientEPSS 0.3%CVE-2026-88032HIGHApplication denial of service via cancellation race in reactive client-side encryption in MongoDB Java DriverEPSS 0.3%CVE-2026-96748HIGHConnection redirection via percent-encoded delimiter injection in connection string hostsEPSS 0.3%CVE-2026-18707MEDIUMImproper Input Validation in MongoDB Aggregation Command Handling Leads to Denial of ServiceEPSS 0.3%CVE-2026-81518HIGHBI Connector Optional Client Certificate Verification Allows Unauthenticated ConnectionsEPSS 0.3%CVE-2026-13068LOWMongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege MisuseEPSS 0.3%CVE-2026-18698MEDIUMImproper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate CommandEPSS 0.2%CVE-2026-18687HIGHImproper Validation in MongoDB Queryable Encryption Maintenance Operation Leads to Denial of Service and Index CorruptionEPSS 0.2%CVE-2026-76794MEDIUMMongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Database MetadataEPSS 0.2%CVE-2026-19003HIGHMongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settingsEPSS 0.2%CVE-2026-19503MEDIUMInsufficient OIDC endpoint validation could invoke unintended local protocol handlersEPSS 0.2%CVE-2026-18704HIGHImproper Authorization in MongoDB Aggregation Framework Allows Read-Only User to Perform Unauthorized Write OperationsEPSS 0.2%CVE-2025-12119MEDIUMBulk write with options may read invalid memoryEPSS 0.2%CVE-2026-18709MEDIUMMissing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data InconsistencyEPSS 0.2%CVE-2026-14881HIGHCompass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flowEPSS 0.2%CVE-2026-13062HIGHMongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded ClustersEPSS 0.2%CVE-2026-96750HIGHShell script injection via server-supplied database name in Open MongoDB shellEPSS 0.2%