PatchSiren

MongoDB CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH MongoDB CVE published 2026-09-24

CVE-2026-96749

A vulnerability in the MongoDB Python Driver's native extension may allow an attacker to cause a write outside the bounds of an allocated buffer, potentially leading to a crash or other unspecified impact. The vulnerability is caused by an integer overflow in the BSON document encoding component, which may occur when a single document is built from an unusually large amount of caller-supplied data. Size a [truncated]

HIGH MongoDB CVE published 2026-09-11

CVE-2026-89099

CVE-2026-89099 is a high-severity vulnerability in MongoDB Server's document value layer, allowing an authenticated user with ordinary read-write privileges to trigger a race condition leading to memory corruption and potential server termination. The vulnerability has a CVSS score of 7.7 and affects the confidentiality, integrity, and availability of the affected server process.

MEDIUM MongoDB CVE published 2026-09-10

CVE-2026-88035

CVE-2026-88035 debrief based on CVE Program and NVD records. The MongoDB C Driver has a size check vulnerability in its client-side authentication path. A large user-name value can cause a buffer overflow, potentially terminating the application. This issue requires specific build and connection configurations. The vulnerability is triggered by an unusually large user-name value, which can cause the appli [truncated]

MEDIUM MongoDB CVE published 2026-09-10

CVE-2026-88034

CVE-2026-88034 Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. This vulnerability allows an authenticated user to influence the identifier passed by an affected application, potentially leading to unauthorized a [truncated]

MEDIUM MongoDB CVE published 2026-09-10

CVE-2026-88033

CVE-2026-88033 debrief based on the supplied source corpus. The CVE record was published on 2026-09-10T19:17:40.673Z and was last modified on 2026-09-16T17:58:43.393Z. The NVD entry is currently Analyzed. Defenders responsible for MongoDB Java Driver deployments, particularly those using versions between 3.3.0 and 5.11.1, should assess exposure and prioritize patching to prevent potential unauthorized acc [truncated]

HIGH MongoDB CVE published 2026-09-10

CVE-2026-88032

A use-after-free vulnerability in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. This issue requires an affected reactive encryption configuration that retrieves KMS credentials on demand. The vulnerability can lead to potential application process ter [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82076

CVE-2026-82076: MongoDB Server Integer Overflow Denial of Service. An authenticated user with ordinary database-level read/write privileges can exploit an integer overflow in the query planning component, causing a denial of service by terminating the server process. This issue affects various MongoDB versions, including 7.0.0 to 7.0.41, 8.0.0 to 8.0.30, 8.2.0 to 8.2.13, 8.3.0 to 8.3.9, and 9.0.0 alpha ve [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82075

An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router port and has not authenticated can supply connection-monitoring parameters that cause the server to expend CPU resources without any rate limiting, degrading or denying service to legitimate clients.

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82074

CVE-2026-82074 debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T17:18:36.403Z and has not been modified since then. The NVD entry is currently Analyzed. Defenders responsible for MongoDB Server instances, especially those with authenticated users having minimal privileges, should assess exposure and prioritize patching to prevent unauthorized read access to collectio [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82073

A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are in use. This issue arises from insufficient validation of an internal command parameter that can be set by external clients, leading to improper skipping of security chec [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82071

CVE-2026-82071 Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process, causing a denial of service via server crash, with potential for further impact including arbi [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82070

CVE-2026-82070 debrief based on CVE Program and NVD records. This high-severity vulnerability in MongoDB Server's diagnostic reporting interface allows authenticated users with monitoring privileges to access insufficiently protected credentials, potentially leading to impersonation of other users, including privileged accounts. The vulnerability exists due to inadequate redaction of credentials in the di [truncated]

MEDIUM MongoDB CVE published 2026-09-08

CVE-2026-82069

CVE-2026-82069 is a medium-severity vulnerability in MongoDB Server's query statistics serialization. Users with monitoring privileges can access unredacted search query text from other users' operations due to an improper conditional check in the serialization logic. This issue allows potential exposure of sensitive query literals through the query statistics interface. MongoDB administrators and securit [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82068

CVE-2026-82068 debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T17:18:35.750Z. MongoDB Server has a security issue that allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands. The crash state is durably persisted, causing the server process to repeatedly crash on restart a [truncated]

CRITICAL MongoDB CVE published 2026-09-08

CVE-2026-82067

CVE-2026-82067 debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T17:18:35.617Z and was last modified on 2026-09-16T20:38:01.447Z. The NVD entry is currently Analyzed. MongoDB Server's configuration validation component mishandles case sensitivity, potentially leaving the authorization subsystem in a default disabled state at startup. This allows unauthenticated users [truncated]

MEDIUM MongoDB CVE published 2026-09-08

CVE-2026-82066

CVE-2026-82066 is a heap out-of-bounds read security issue in MongoDB Server's query planning component. An authenticated user with database read and write privileges can trigger this issue through crafted query operations, causing the server to read memory beyond allocated buffer boundaries. The revealed memory contents may be partially observable through diagnostic query statistics output.

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82065

CVE-2026-82065 is a security issue in the MongoDB Server's storage engine integration layer that allows an authenticated user with collection creation privileges to cause a persistent denial of service. The issue is caused by insufficient validation of user-supplied storage configuration options, which can trigger a fatal assertion failure when the metadata is subsequently read by diagnostic operations.

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82064

A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authentication, and the assertion's assumptions about internal state do not hold for all member configurations, causing the server process to terminate.

MEDIUM MongoDB CVE published 2026-09-08

CVE-2026-82063

CVE-2026-82063 is a use-after-free issue in MongoDB Server's cursor management component that allows an authenticated user to cause a denial of service. The issue arises under specific timing conditions during cursor operations, leading to a server process crash. MongoDB Server administrators, security teams, and IT professionals responsible for maintaining MongoDB deployments should assess exposure and t [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82062

CVE-2026-82062 debrief: MongoDB Server security issue allows authenticated users with elevated internal privileges to bypass a disabled feature gate, enabling execution of container operations and direct storage-engine writes to arbitrary internal storage tables. This security issue can lead to potential data tampering, disruption of operations, and impact on data integrity and confidentiality in MongoDB [truncated]

LOW MongoDB CVE published 2026-09-08

CVE-2026-82060

CVE-2026-82060 debrief based on CVE Program and NVD records. The vulnerability involves insufficient validation of shard key values in MongoDB, allowing authenticated users to store specially crafted documents. This could lead to incorrect post-image documents or fatal errors in change stream consumers. Defenders should verify MongoDB versions and review shard key values. The CVE record was published on 2 [truncated]

MEDIUM MongoDB CVE published 2026-09-08

CVE-2026-82059

CVE-2026-82059 debrief based on CVE Program and NVD records. The vulnerability affects MongoDB Server, allowing an authenticated user with read-only privileges to trigger a denial of service. MongoDB administrators and security teams should assess exposure and prioritize patching. The issue involves an internal aggregation expression incorrectly registered as accessible to any authenticated user. A malfor [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82058

A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON document containing an array with a malformed numeric field name fails a $jsonSchema items type constraint, the error generation path performs unsafe numeric conversion on the user-controlled field name without proper exception handling, resulting [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82057

A security issue in MongoDB allows an authenticated user with readWrite privileges to crash the mongod server process by specifying a custom WiredTiger storage configuration option with an incompatible value during collection creation. This causes a type confusion in the storage engine layer, leading to corrupted memory interpretation and a server crash when documents are read from the misconfigured colle [truncated]

MEDIUM MongoDB CVE published 2026-09-08

CVE-2026-82056

A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index lifecycle operations, a raw pointer to internal text index metadata may be dereferenced after the underlying structures have been freed, leading to a server crash. An authenticated user with readWrite privileges can trigger this condition throu [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82055

A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a specially crafted GeoJSON document is inserted into a collection with a 2dsphere index, an inconsistency in geometry parsing can leave an internal object in an invalid, partially initialized state. During subsequent index key generation, access to this improperly initi [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82054

A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumptio [truncated]

HIGH MongoDB CVE published 2026-09-08

CVE-2026-82053

A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configurati [truncated]

MEDIUM MongoDB CVE published 2026-08-28

CVE-2026-81533

A memory-safety issue occurs in the MongoDB BI Connector ODBC Driver when handling SQL statements with long digit sequences following a LIMIT clause, specifically when the driver's optional prefetch setting is enabled. This could lead to the hosting application process terminating unexpectedly or corrupting adjacent memory. The issue arises from the driver's handling of unusually long digit sequences, whi [truncated]

HIGH MongoDB CVE published 2026-08-28

CVE-2026-81532

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that buffer is overwritten with user-supplied content. This can terminate the hosting applica [truncated]