Vulnerabilidades em MongoDB
162 resultadosAnálise Vexday
MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.
CVE-2026-84962MEDIUMAuthenticated KMS request forgery via CRLF injection in GCP key identifier stringsEPSS 0.2%CVE-2026-18712HIGHImproper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other CollectionsEPSS 0.2%CVE-2025-11695HIGHConfiguration may unexpectedly disable certificate validationEPSS 0.2%CVE-2026-9735MEDIUMKeyfile contents are in MongoDB Server logsEPSS 0.2%CVE-2025-12100HIGHMongoDB BI Connector ODBC driver installation via MSI may leave ACLs unset on custom installation directoriesEPSS 0.2%CVE-2026-9741HIGHClient side encryption fails to encrypt values in a $vectorSearchEPSS 0.2%CVE-2026-9751MEDIUMSensitive data could be written to mongod.logEPSS 0.2%CVE-2026-18710HIGHCleartext Storage of Sensitive Information in MongoDB Driver Logging During Client InitializationEPSS 0.2%CVE-2026-18703LOWImproper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication MethodEPSS 0.1%CVE-2026-84966MEDIUMBSON element injection via NUL-embedded document keys in builder appendEPSS 0.1%CVE-2026-88035MEDIUMHeap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C DriverEPSS 0.1%CVE-2025-11575HIGHMongoDB Atlas SQL ODBC driver installation via MSI may leave ACLs unset on custom installation directoriesEPSS 0.1%CVE-2026-13070MEDIUMImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process TerminationEPSS 0.1%CVE-2026-96749HIGHHeap out-of-bounds write via signed size overflow in BSON document encodingEPSS 0.1%CVE-2026-96747MEDIUMForced local Unix socket connection via dot-sock KMS endpoint in client-side field encryptionEPSS 0.1%CVE-2026-84965MEDIUMHeap write primitive via size round-up wrap during JSON parsing on 32-bit buildsEPSS 0.1%CVE-2026-84970MEDIUMHeap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parserEPSS 0.1%CVE-2026-19502MEDIUMInsufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLIEPSS 0.1%CVE-2026-75573MEDIUMMongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Are SuppliedEPSS 0.1%CVE-2026-81523LOWCross-tenant database retargeting via dot/NUL injection in namespace strings in libmongocryptEPSS 0.1%