mongodb
107 known vulnerabilities affecting mongodb products.
Products
mongodb 85
bi_connector_odbc_driver 7
c_driver 3
mongosql_transition_readiness_tool 3
libmongocrypt 3
java_driver 2
c\+\+_driver 2
php_driver 1
mongodb_client_encryption 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-18692 | Medium | 0.4% | 8.8 | An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow… | |
| CVE-2026-13072 | Medium | 0.4% | 8.1 | When compute mode is enabled on a standalone mongod instance, insufficient valid… | |
| CVE-2026-19001 | Medium | 0.4% | 9.8 | The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-siz… | |
| CVE-2026-13059 | Medium | 0.4% | 8.1 | An authenticated user with low privileges may be able to perform unauthorized re… | |
| CVE-2026-19004 | Medium | 0.4% | 8.1 | An application using the MongoDB BI Connector ODBC Driver may experience a memor… | |
| CVE-2026-9742 | Medium | 0.3% | 7.5 | When OIDC authentication is enabled in configuration, clients may set specific v… | |
| CVE-2026-9740 | Medium | 0.3% | 7.5 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthentica… | |
| CVE-2026-13078 | Medium | 0.3% | 7.7 | A vulnerability was discovered in MongoDB Server where the server-side MozJS scr… | |
| CVE-2026-18697 | Medium | 0.3% | 7.5 | An issue in MongoDB Server's aggregation framework could allow an unauthenticate… | |
| CVE-2026-19002 | Medium | 0.3% | 8.1 | A missing bounds check when parsing stored procedure parameter metadata in the M… | |
| CVE-2026-82071 | Medium | 0.3% | 8.1 | Insufficient validation of storage engine configuration options in MongoDB Serve… | |
| CVE-2026-9753 | Medium | 0.3% | 8.1 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute… | |
| CVE-2026-82061 | Medium | 0.3% | 8.1 | A use-after-free security issue exists in the server's query execution memory tr… | |
| CVE-2026-81532 | Medium | 0.3% | 8.8 | A user able to submit SQL through an application using the MongoDB Connector for… | |
| CVE-2026-82064 | Medium | 0.3% | 7.5 | A security issue in MongoDB Server allows an unauthenticated network user to cau… | |
| CVE-2026-82075 | Medium | 0.3% | 7.5 | An uncontrolled resource consumption weakness exists in the request-handling pat… | |
| CVE-2026-18688 | Medium | 0.3% | 7.1 | An issue in MongoDB Server's aggregation framework could allow an authenticated … | |
| CVE-2026-18694 | Medium | 0.3% | 7.1 | An issue in MongoDB Server's geospatial query processing could allow an authenti… | |
| CVE-2026-82067 | Medium | 0.3% | 8.1 | Improper handling of case sensitivity in the configuration validation component … | |
| CVE-2026-13077 | Medium | 0.3% | 7.1 | A missing bounds check in the BSON CodeWScope element accessors allows an attack… | |
| CVE-2026-88036 | Medium | 0.3% | 8.3 | Improper neutralization of special elements in data query logic in the GridFS co… | |
| CVE-2026-18690 | Medium | 0.3% | 8.1 | An issue in MongoDB Server could allow an authenticated user with a limited data… | |
| CVE-2026-88033 | Medium | 0.3% | 8.3 | Improper neutralization of special elements in data query logic in the GridFS co… | |
| CVE-2026-88034 | Medium | 0.3% | 8.3 | Improper neutralization of special elements in data query logic in the GridFS co… | |
| CVE-2026-18693 | Medium | 0.2% | 7.6 | An issue in MongoDB Server's handling of timeseries collections could allow an a… | |
| CVE-2026-82053 | Medium | 0.2% | 8.1 | A security issue exists in MongoDB's LDAP authorization integration where pooled… | |
| CVE-2026-18691 | Medium | 0.2% | 8.8 | An issue in MongoDB Server's intra-cluster connection setup could allow a party … | |
| CVE-2026-81533 | Medium | 0.2% | 7.1 | An application using the MongoDB BI Connector ODBC Driver may encounter a memory… | |
| CVE-2026-18687 | Medium | 0.2% | 7.1 | MongoDB Server's handling of a Queryable Encryption maintenance operation did no… | |
| CVE-2026-19003 | Medium | 0.2% | 7.8 | A data source definition containing an over-length file path setting may cause t… | |
| CVE-2026-13065 | Low | 0.5% | 6.5 | A user with read-only privileges is able to craft an aggregation pipeline using … | |
| CVE-2026-13064 | Low | 0.5% | 6.5 | Certain query operations involving deeply nested $jsonSchema constructs can trig… | |
| CVE-2026-13076 | Low | 0.4% | 6.5 | An authenticated user can cause a {{mongod}} process to be terminated by the ope… | |
| CVE-2026-13056 | Low | 0.4% | 6.5 | Using expressions that generate large arrays it is possible to craft a query tha… | |
| CVE-2026-13060 | Low | 0.4% | 6.5 | An authenticated user with limited read privileges may be able to access documen… | |
| CVE-2026-13066 | Low | 0.4% | 6.5 | Improper handling of DBPointer objects during BSON serialization in MongoDB's se… | |
| CVE-2026-9750 | Low | 0.4% | 6.5 | An authenticated user can cause a MongoDB server to crash or return incorrect re… | |
| CVE-2026-82052 | Low | 0.4% | 6.5 | The $regexFindAll expression can be used by an authenticated user who can run ag… | |
| CVE-2026-18706 | Low | 0.3% | 6.6 | An issue in MongoDB Server's $graphLookup aggregation stage could allow an authe… | |
| CVE-2026-9748 | Low | 0.3% | 6.5 | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to sign… | |
| CVE-2026-82062 | Low | 0.3% | 5.5 | A security issue in MongoDB Server allows an authenticated user with elevated in… | |
| CVE-2026-18888 | Low | 0.3% | 6.5 | The MongoDB BI Connector ODBC Driver converts floating point column values into … | |
| CVE-2026-9743 | Low | 0.3% | 6.5 | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field nul… | |
| CVE-2026-18701 | Low | 0.3% | 6.5 | An issue in MongoDB Server's query subsystem could allow an authenticated user w… | |
| CVE-2026-82057 | Low | 0.3% | 6.5 | A security issue was discovered in MongoDB where an authenticated user with read… | |
| CVE-2026-13074 | Low | 0.3% | 5.3 | An unauthenticated remote client can cause excessive CPU consumption on a MongoD… | |
| CVE-2026-82076 | Low | 0.3% | 6.5 | An integer overflow in the query planning component of MongoDB Server can allow … | |
| CVE-2026-13055 | Low | 0.3% | 6.5 | The `$_internalIndexKey` aggregation expression can be used by any authenticated… | |
| CVE-2026-18695 | Low | 0.3% | 6.5 | An issue in MongoDB Server's handling of certain query predicates against time-s… | |
| CVE-2026-18699 | Low | 0.3% | 6.5 | An issue in MongoDB Server's query planner could allow an authenticated user wit… |
Page 1 of 3
Next →