Mongodb
58 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-18888
HIGH 7.1
Bi Connector Odbc Driver — The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the…
2026-08-12
CVE-2026-19001
CRITICAL 9.5
Bi Connector Odbc Driver — The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application s…
2026-08-12
CVE-2026-19002
HIGH 8.8
Bi Connector Odbc Driver — A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Drive…
2026-08-12
CVE-2026-19003
HIGH 8.4
Bi Connector Odbc Driver — A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC D…
2026-08-12
CVE-2026-19004
HIGH 8.8
Bi Connector Odbc Driver — An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing…
2026-08-12
CVE-2026-19502
MEDIUM 6.8
Schema Builder Cli — MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is …
2026-08-12
CVE-2026-19503
MEDIUM 6.3
Atlas Sql Odbc Driver — MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and t…
2026-08-12
CVE-2026-18687
HIGH 7.1
Mongodb Server — MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain re…
2026-08-11
CVE-2026-18688
HIGH 7.1
Mongodb Server — An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-boun…
2026-08-11
CVE-2026-18690
HIGH 7.2
Mongodb Server — An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an…
2026-08-11
CVE-2026-18691
CRITICAL 9
Mongodb Server — An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access t…
2026-08-11
CVE-2026-18692
HIGH 7.7
Mongodb Server — An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with wr…
2026-08-11
CVE-2026-18693
HIGH 7.2
Mongodb Server — An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write p…
2026-08-11
CVE-2026-18694
HIGH 7.1
Mongodb Server — An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileg…
2026-08-11
CVE-2026-18695
HIGH 7.1
Mongodb Server — An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaF…
2026-08-11
CVE-2026-18696
HIGH 7
Mongodb Server — An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default priv…
2026-08-11
CVE-2026-18697
HIGH 8.7
Mongodb Server — An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (rou…
2026-08-11
CVE-2026-18698
MEDIUM 5.3
Mongodb Server — An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an…
2026-08-11
CVE-2026-18699
MEDIUM 6
Mongodb Server — An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cau…
2026-08-11
CVE-2026-18700
MEDIUM 6
Mongodb Server — An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to …
2026-08-11
CVE-2026-18701
HIGH 7.1
Mongodb Server — An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause t…
2026-08-11
CVE-2026-18702
MEDIUM 5.3
Mongodb Server — An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modif…
2026-08-11
CVE-2026-18703
LOW 2.3
Mongodb Server — An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user accoun…
2026-08-11
CVE-2026-18704
HIGH 7.1
Mongodb Server — An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges…
2026-08-11
CVE-2026-18705
HIGH 7.1
Mongodb Server — An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to…
2026-08-11
CVE-2026-18706
HIGH 7.5
Mongodb Server — An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue ag…
2026-08-11
CVE-2026-18707
MEDIUM 5.3
Mongodb Server — An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to ca…
2026-08-11
CVE-2026-18708
MEDIUM 5.3
Mongodb Server — An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileg…
2026-08-11
CVE-2026-18709
MEDIUM 5.9
Mongodb Server — An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improper…
2026-08-11
CVE-2026-18710
HIGH 8.2
Mongodb Driver — A MongoDB driver component could write sensitive configuration information, including a credential used for ou…
2026-08-11
CVE-2026-18711
HIGH 7.1
Mongodb Server — An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write priv…
2026-08-11
CVE-2026-18712
HIGH 7.2
Mongodb Server — An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user wit…
2026-08-11
CVE-2026-13055
HIGH 7.1
Mongodb Server — The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB serve…
2026-07-22
CVE-2026-13056
HIGH 7.1
Mongodb Server — Using expressions that generate large arrays it is possible to craft a query that creates very large intermedi…
2026-07-22
CVE-2026-13057
MEDIUM 6
Mongodb Server — An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access contr…
2026-07-22
CVE-2026-13058
HIGH 7.1
Mongodb Server — An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by send…
2026-07-22
CVE-2026-13059
HIGH 8.6
Mongodb Server — An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protect…
2026-07-22
CVE-2026-13060
HIGH 7.1
Mongodb Server — An authenticated user with limited read privileges may be able to access documents from collections they are n…
2026-07-22
CVE-2026-13061
MEDIUM 5.3
Mongodb Server — An authenticated user may be able to view session metadata belonging to other users on the system through the …
2026-07-22
CVE-2026-13062
HIGH 7.1
Mongodb Server — An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify…
2026-07-22
CVE-2026-13063
MEDIUM 5.3
Mongodb Server — An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an …
2026-07-22
CVE-2026-13064
HIGH 7.1
Mongodb Server — Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consu…
2026-07-22
CVE-2026-13065
HIGH 7.1
Mongodb Server — A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window functio…
2026-07-22
CVE-2026-13066
HIGH 7.1
Mongodb Server — Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine ca…
2026-07-22
CVE-2026-13067
HIGH 7.2
Mongodb Server — When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates ma…
2026-07-22
CVE-2026-13068
LOW 2.3
Mongodb Server — An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to te…
2026-07-22
CVE-2026-13069
HIGH 7.1
Mongodb Server — An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by s…
2026-07-22
CVE-2026-13070
MEDIUM 6
Mongodb Server — A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OC…
2026-07-22
CVE-2026-13071
HIGH 7.1
Mongodb Server — An authenticated user with read access can cause the mongod process to be terminated through certain aggregati…
2026-07-22
CVE-2026-13072
CRITICAL 9.2
Mongodb Server — When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BS…
2026-07-22
CVE-2026-13073
MEDIUM 5.3
Mongodb Server — An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuin…
2026-07-22
CVE-2026-13074
MEDIUM 6.9
Mongodb Server — An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific…
2026-07-22
CVE-2026-13075
HIGH 7.1
Mongodb Server — An authenticated user can cause the mongod process to be terminated by the operating system under memory press…
2026-07-22
CVE-2026-13076
HIGH 7.1
Mongodb Server — An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pre…
2026-07-22
CVE-2026-13077
HIGH 7.1
Mongodb Server — A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds…
2026-07-22
CVE-2026-13078
MEDIUM 6.3
Mongodb Server — A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally …
2026-07-22
CVE-2026-14881
HIGH 8.4
Mongodb Compass — When importing connections in Compass it is possible to override some connection options that are otherwise ca…
2026-07-22
CVE-2026-9737
HIGH 7.1
Mongodb Server — During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly ha…
2026-07-22