← All vendors

mongodb

107 known vulnerabilities affecting mongodb products.

Products

mongodb 85 bi_connector_odbc_driver 7 c_driver 3 mongosql_transition_readiness_tool 3 libmongocrypt 3 java_driver 2 c\+\+_driver 2 php_driver 1 mongodb_client_encryption 1

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-18692 Medium 0.4% 8.8 An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow…
CVE-2026-13072 Medium 0.4% 8.1 When compute mode is enabled on a standalone mongod instance, insufficient valid…
CVE-2026-19001 Medium 0.4% 9.8 The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-siz…
CVE-2026-13059 Medium 0.4% 8.1 An authenticated user with low privileges may be able to perform unauthorized re…
CVE-2026-19004 Medium 0.4% 8.1 An application using the MongoDB BI Connector ODBC Driver may experience a memor…
CVE-2026-9742 Medium 0.3% 7.5 When OIDC authentication is enabled in configuration, clients may set specific v…
CVE-2026-9740 Medium 0.3% 7.5 A vulnerability in MongoDB Server's BSON validation logic allows an unauthentica…
CVE-2026-13078 Medium 0.3% 7.7 A vulnerability was discovered in MongoDB Server where the server-side MozJS scr…
CVE-2026-18697 Medium 0.3% 7.5 An issue in MongoDB Server's aggregation framework could allow an unauthenticate…
CVE-2026-19002 Medium 0.3% 8.1 A missing bounds check when parsing stored procedure parameter metadata in the M…
CVE-2026-82071 Medium 0.3% 8.1 Insufficient validation of storage engine configuration options in MongoDB Serve…
CVE-2026-9753 Medium 0.3% 8.1 The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute…
CVE-2026-82061 Medium 0.3% 8.1 A use-after-free security issue exists in the server's query execution memory tr…
CVE-2026-81532 Medium 0.3% 8.8 A user able to submit SQL through an application using the MongoDB Connector for…
CVE-2026-82064 Medium 0.3% 7.5 A security issue in MongoDB Server allows an unauthenticated network user to cau…
CVE-2026-82075 Medium 0.3% 7.5 An uncontrolled resource consumption weakness exists in the request-handling pat…
CVE-2026-18688 Medium 0.3% 7.1 An issue in MongoDB Server's aggregation framework could allow an authenticated …
CVE-2026-18694 Medium 0.3% 7.1 An issue in MongoDB Server's geospatial query processing could allow an authenti…
CVE-2026-82067 Medium 0.3% 8.1 Improper handling of case sensitivity in the configuration validation component …
CVE-2026-13077 Medium 0.3% 7.1 A missing bounds check in the BSON CodeWScope element accessors allows an attack…
CVE-2026-88036 Medium 0.3% 8.3 Improper neutralization of special elements in data query logic in the GridFS co…
CVE-2026-18690 Medium 0.3% 8.1 An issue in MongoDB Server could allow an authenticated user with a limited data…
CVE-2026-88033 Medium 0.3% 8.3 Improper neutralization of special elements in data query logic in the GridFS co…
CVE-2026-88034 Medium 0.3% 8.3 Improper neutralization of special elements in data query logic in the GridFS co…
CVE-2026-18693 Medium 0.2% 7.6 An issue in MongoDB Server's handling of timeseries collections could allow an a…
CVE-2026-82053 Medium 0.2% 8.1 A security issue exists in MongoDB's LDAP authorization integration where pooled…
CVE-2026-18691 Medium 0.2% 8.8 An issue in MongoDB Server's intra-cluster connection setup could allow a party …
CVE-2026-81533 Medium 0.2% 7.1 An application using the MongoDB BI Connector ODBC Driver may encounter a memory…
CVE-2026-18687 Medium 0.2% 7.1 MongoDB Server's handling of a Queryable Encryption maintenance operation did no…
CVE-2026-19003 Medium 0.2% 7.8 A data source definition containing an over-length file path setting may cause t…
CVE-2026-13065 Low 0.5% 6.5 A user with read-only privileges is able to craft an aggregation pipeline using …
CVE-2026-13064 Low 0.5% 6.5 Certain query operations involving deeply nested $jsonSchema constructs can trig…
CVE-2026-13076 Low 0.4% 6.5 An authenticated user can cause a {{mongod}} process to be terminated by the ope…
CVE-2026-13056 Low 0.4% 6.5 Using expressions that generate large arrays it is possible to craft a query tha…
CVE-2026-13060 Low 0.4% 6.5 An authenticated user with limited read privileges may be able to access documen…
CVE-2026-13066 Low 0.4% 6.5 Improper handling of DBPointer objects during BSON serialization in MongoDB's se…
CVE-2026-9750 Low 0.4% 6.5 An authenticated user can cause a MongoDB server to crash or return incorrect re…
CVE-2026-82052 Low 0.4% 6.5 The $regexFindAll expression can be used by an authenticated user who can run ag…
CVE-2026-18706 Low 0.3% 6.6 An issue in MongoDB Server's $graphLookup aggregation stage could allow an authe…
CVE-2026-9748 Low 0.3% 6.5 The $_internalConvertBucketIndexStats stage used PauseExecution as a way to sign…
CVE-2026-82062 Low 0.3% 5.5 A security issue in MongoDB Server allows an authenticated user with elevated in…
CVE-2026-18888 Low 0.3% 6.5 The MongoDB BI Connector ODBC Driver converts floating point column values into …
CVE-2026-9743 Low 0.3% 6.5 In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field nul…
CVE-2026-18701 Low 0.3% 6.5 An issue in MongoDB Server's query subsystem could allow an authenticated user w…
CVE-2026-82057 Low 0.3% 6.5 A security issue was discovered in MongoDB where an authenticated user with read…
CVE-2026-13074 Low 0.3% 5.3 An unauthenticated remote client can cause excessive CPU consumption on a MongoD…
CVE-2026-82076 Low 0.3% 6.5 An integer overflow in the query planning component of MongoDB Server can allow …
CVE-2026-13055 Low 0.3% 6.5 The `$_internalIndexKey` aggregation expression can be used by any authenticated…
CVE-2026-18695 Low 0.3% 6.5 An issue in MongoDB Server's handling of certain query predicates against time-s…
CVE-2026-18699 Low 0.3% 6.5 An issue in MongoDB Server's query planner could allow an authenticated user wit…
Page 1 of 3 Next →