mongodb
107 known vulnerabilities affecting mongodb products.
Products
mongodb 85
bi_connector_odbc_driver 7
c_driver 3
mongosql_transition_readiness_tool 3
libmongocrypt 3
java_driver 2
c\+\+_driver 2
php_driver 1
mongodb_client_encryption 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-82065 | Low | 0.3% | 6.5 | A security issue in the MongoDB Server's storage engine integration layer allows… | |
| CVE-2026-82054 | Low | 0.3% | 6.5 | A security issue exists in MongoDB server's JSON Pointer parser used during $jso… | |
| CVE-2026-82068 | Low | 0.3% | 6.5 | A security issue in MongoDB Server allows an authenticated user with write privi… | |
| CVE-2026-18700 | Low | 0.3% | 6.5 | An issue in MongoDB Server's geospatial validation could allow an authenticated … | |
| CVE-2026-82058 | Low | 0.3% | 6.5 | A flaw in MongoDB's JSON Schema validation error generation code allows an authe… | |
| CVE-2026-18699 | Low | 0.3% | 6.5 | An issue in MongoDB Server's query planner could allow an authenticated user wit… | |
| CVE-2026-82069 | Low | 0.3% | 2.7 | A security issue in MongoDB Server's query statistics serialization on the route… | |
| CVE-2026-13061 | Low | 0.3% | 4.3 | An authenticated user may be able to view session metadata belonging to other us… | |
| CVE-2026-18708 | Low | 0.3% | 6.4 | An issue in MongoDB Server's JavaScript scripting engine could allow an authenti… | |
| CVE-2026-18696 | Low | 0.3% | 6.5 | An issue in MongoDB Server's applyOps command could allow an authenticated user … | |
| CVE-2026-82066 | Low | 0.3% | 4.3 | A heap out-of-bounds read security issue exists in the query planning component … | |
| CVE-2026-9749 | Low | 0.3% | 6.5 | This issue can occur when running an aggregation pipeline that uses the internal… | |
| CVE-2026-9746 | Low | 0.3% | 6.5 | When using $changestreams and $_requestReshardingResumeToken with the exchange o… | |
| CVE-2026-9752 | Low | 0.3% | 6.5 | An authorized user could trigger a server crash by running a query with a 2dsphe… | |
| CVE-2026-9747 | Low | 0.3% | 6.5 | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations t… | |
| CVE-2026-13057 | Low | 0.3% | 5.3 | An issue in the server’s Atlas Search integration allows an authenticated user t… | |
| CVE-2026-18705 | Low | 0.3% | 6.5 | An issue in MongoDB Server's Atlas Vector Search feature could allow an authenti… | |
| CVE-2026-82063 | Low | 0.3% | 5.3 | A use-after-free security issue in the cursor management component of MongoDB Se… | |
| CVE-2026-82059 | Low | 0.3% | 5.3 | An internal aggregation expression in MongoDB Server was incorrectly registered … | |
| CVE-2026-18707 | Low | 0.3% | 4.3 | An issue in MongoDB Server could allow an authenticated user, including one with… | |
| CVE-2026-76797 | Low | 0.3% | 6.3 | The MongoSQL Transition Readiness Tool writes database and collection names into… | |
| CVE-2026-13071 | Low | 0.3% | 6.5 | An authenticated user with read access can cause the mongod process to be termin… | |
| CVE-2026-82056 | Low | 0.2% | 5.3 | A race condition in MongoDB server's text index query parsing can cause a heap u… | |
| CVE-2026-13075 | Low | 0.2% | 6.5 | An authenticated user can cause the mongod process to be terminated by the opera… | |
| CVE-2026-82073 | Low | 0.2% | 6.5 | A security issue in the MongoDB Server aggregation framework allows an authentic… | |
| CVE-2026-82074 | Low | 0.2% | 6.5 | MongoDB Server contains an incorrect authorization vulnerability in the aggregat… | |
| CVE-2026-82070 | Low | 0.2% | 6.5 | A security issue in MongoDB Server's diagnostic reporting interface allows an au… | |
| CVE-2026-82060 | Low | 0.2% | 5.4 | In MongoDB, insufficient validation of shard key values during document insertio… | |
| CVE-2026-13058 | Low | 0.2% | 6.5 | An authenticated user with basic write privileges can cause the mongod process t… | |
| CVE-2026-13063 | Low | 0.2% | 4.3 | An authenticated user with standard read/write privileges can cause the mongod p… | |
| CVE-2026-9754 | Low | 0.2% | 6.5 | An authenticated user with the read role may read limited amounts of uninitializ… | |
| CVE-2026-13073 | Low | 0.2% | 4.3 | An authenticated user with read-only privileges can cause the mongod process to … | |
| CVE-2026-76798 | Low | 0.2% | 6.3 | The MongoSQL Transition Readiness Tool writes query text and user names read fro… | |
| CVE-2026-18704 | Low | 0.2% | 6.5 | An issue in MongoDB Server's aggregation framework could allow an authenticated … | |
| CVE-2021-20327 | Low | 0.2% | 6.4 | A specific version of the Node.js mongodb-client-encryption module does not perf… | |
| CVE-2026-18702 | Low | 0.2% | 6.4 | An issue in MongoDB Server could allow an authenticated user with limited, datab… | |
| CVE-2026-84968 | Low | 0.2% | 5.3 | An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver m… | |
| CVE-2026-13062 | Low | 0.2% | 6.5 | An authenticated user with write privileges on a Queryable Encryption-enabled co… | |
| CVE-2026-13069 | Low | 0.2% | 6.5 | An authenticated user can cause excessive CPU consumption or out-of-memory condi… | |
| CVE-2026-18698 | Low | 0.2% | 5.4 | An issue in MongoDB Server could allow an authenticated user with a limited data… | |
| CVE-2026-84969 | Low | 0.2% | 3.7 | A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C … | |
| CVE-2026-76794 | Low | 0.2% | 4.6 | MongoSQL Transition Readiness Tool does not sufficiently encode database metadat… | |
| CVE-2026-84971 | Low | 0.2% | 6.5 | Improper handling of an unexpected value size in the decryption path of a client… | |
| CVE-2026-84967 | Low | 0.2% | 4.3 | A component of the MongoDB extension for Visual Studio Code does not neutralize … | |
| CVE-2026-88032 | Low | 0.2% | 5.9 | A use-after-free in the reactive client-side encryption component of the MongoDB… | |
| CVE-2026-13068 | Low | 0.1% | 4.2 | An authenticated user holding cursor termination privileges on one database may … | |
| CVE-2026-13070 | Low | 0.1% | 5.3 | A MongoDB server initiating an outbound TLS connection may terminate abnormally … | |
| CVE-2026-18709 | Low | 0.1% | 6.4 | An issue in MongoDB Server could allow an authenticated user with direct network… | |
| CVE-2026-9735 | Low | 0.1% | 5.5 | MongoDB server may log authentication parameters, including credentials, to the … | |
| CVE-2026-84962 | Low | 0.1% | 4.2 | An unauthorized user with key vault write access may cause an authorized client … |