← Browse

Mongodb

58 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-18888 HIGH 7.1 Bi Connector Odbc Driver — The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the… 2026-08-12 CVE-2026-19001 CRITICAL 9.5 Bi Connector Odbc Driver — The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application s… 2026-08-12 CVE-2026-19002 HIGH 8.8 Bi Connector Odbc Driver — A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Drive… 2026-08-12 CVE-2026-19003 HIGH 8.4 Bi Connector Odbc Driver — A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC D… 2026-08-12 CVE-2026-19004 HIGH 8.8 Bi Connector Odbc Driver — An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing… 2026-08-12 CVE-2026-19502 MEDIUM 6.8 Schema Builder Cli — MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is … 2026-08-12 CVE-2026-19503 MEDIUM 6.3 Atlas Sql Odbc Driver — MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and t… 2026-08-12 CVE-2026-18687 HIGH 7.1 Mongodb Server — MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain re… 2026-08-11 CVE-2026-18688 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-boun… 2026-08-11 CVE-2026-18690 HIGH 7.2 Mongodb Server — An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an… 2026-08-11 CVE-2026-18691 CRITICAL 9 Mongodb Server — An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access t… 2026-08-11 CVE-2026-18692 HIGH 7.7 Mongodb Server — An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with wr… 2026-08-11 CVE-2026-18693 HIGH 7.2 Mongodb Server — An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write p… 2026-08-11 CVE-2026-18694 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileg… 2026-08-11 CVE-2026-18695 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaF… 2026-08-11 CVE-2026-18696 HIGH 7 Mongodb Server — An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default priv… 2026-08-11 CVE-2026-18697 HIGH 8.7 Mongodb Server — An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (rou… 2026-08-11 CVE-2026-18698 MEDIUM 5.3 Mongodb Server — An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an… 2026-08-11 CVE-2026-18699 MEDIUM 6 Mongodb Server — An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cau… 2026-08-11 CVE-2026-18700 MEDIUM 6 Mongodb Server — An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to … 2026-08-11 CVE-2026-18701 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause t… 2026-08-11 CVE-2026-18702 MEDIUM 5.3 Mongodb Server — An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modif… 2026-08-11 CVE-2026-18703 LOW 2.3 Mongodb Server — An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user accoun… 2026-08-11 CVE-2026-18704 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges… 2026-08-11 CVE-2026-18705 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to… 2026-08-11 CVE-2026-18706 HIGH 7.5 Mongodb Server — An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue ag… 2026-08-11 CVE-2026-18707 MEDIUM 5.3 Mongodb Server — An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to ca… 2026-08-11 CVE-2026-18708 MEDIUM 5.3 Mongodb Server — An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileg… 2026-08-11 CVE-2026-18709 MEDIUM 5.9 Mongodb Server — An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improper… 2026-08-11 CVE-2026-18710 HIGH 8.2 Mongodb Driver — A MongoDB driver component could write sensitive configuration information, including a credential used for ou… 2026-08-11 CVE-2026-18711 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write priv… 2026-08-11 CVE-2026-18712 HIGH 7.2 Mongodb Server — An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user wit… 2026-08-11 CVE-2026-13055 HIGH 7.1 Mongodb Server — The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB serve… 2026-07-22 CVE-2026-13056 HIGH 7.1 Mongodb Server — Using expressions that generate large arrays it is possible to craft a query that creates very large intermedi… 2026-07-22 CVE-2026-13057 MEDIUM 6 Mongodb Server — An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access contr… 2026-07-22 CVE-2026-13058 HIGH 7.1 Mongodb Server — An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by send… 2026-07-22 CVE-2026-13059 HIGH 8.6 Mongodb Server — An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protect… 2026-07-22 CVE-2026-13060 HIGH 7.1 Mongodb Server — An authenticated user with limited read privileges may be able to access documents from collections they are n… 2026-07-22 CVE-2026-13061 MEDIUM 5.3 Mongodb Server — An authenticated user may be able to view session metadata belonging to other users on the system through the … 2026-07-22 CVE-2026-13062 HIGH 7.1 Mongodb Server — An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify… 2026-07-22 CVE-2026-13063 MEDIUM 5.3 Mongodb Server — An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an … 2026-07-22 CVE-2026-13064 HIGH 7.1 Mongodb Server — Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consu… 2026-07-22 CVE-2026-13065 HIGH 7.1 Mongodb Server — A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window functio… 2026-07-22 CVE-2026-13066 HIGH 7.1 Mongodb Server — Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine ca… 2026-07-22 CVE-2026-13067 HIGH 7.2 Mongodb Server — When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates ma… 2026-07-22 CVE-2026-13068 LOW 2.3 Mongodb Server — An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to te… 2026-07-22 CVE-2026-13069 HIGH 7.1 Mongodb Server — An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by s… 2026-07-22 CVE-2026-13070 MEDIUM 6 Mongodb Server — A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OC… 2026-07-22 CVE-2026-13071 HIGH 7.1 Mongodb Server — An authenticated user with read access can cause the mongod process to be terminated through certain aggregati… 2026-07-22 CVE-2026-13072 CRITICAL 9.2 Mongodb Server — When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BS… 2026-07-22 CVE-2026-13073 MEDIUM 5.3 Mongodb Server — An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuin… 2026-07-22 CVE-2026-13074 MEDIUM 6.9 Mongodb Server — An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific… 2026-07-22 CVE-2026-13075 HIGH 7.1 Mongodb Server — An authenticated user can cause the mongod process to be terminated by the operating system under memory press… 2026-07-22 CVE-2026-13076 HIGH 7.1 Mongodb Server — An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pre… 2026-07-22 CVE-2026-13077 HIGH 7.1 Mongodb Server — A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds… 2026-07-22 CVE-2026-13078 MEDIUM 6.3 Mongodb Server — A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally … 2026-07-22 CVE-2026-14881 HIGH 8.4 Mongodb Compass — When importing connections in Compass it is possible to override some connection options that are otherwise ca… 2026-07-22 CVE-2026-9737 HIGH 7.1 Mongodb Server — During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly ha… 2026-07-22