PatchSiren

MongoDB, Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM MongoDB Inc. CVE published 2026-09-17

CVE-2026-92758

CVE-2026-92758 debrief based on the supplied source corpus. The CVE record was published on 2026-09-17T20:18:57.433Z and has not been modified since then. This medium-severity vulnerability in the MongoDB Entity Framework Core Provider can result in sensitive information exposure through logs when logging mode is set to DEBUG or a malformed MongoDB connection string is used. Defenders and security teams r [truncated]

MEDIUM MongoDB Inc. CVE published 2026-09-17

CVE-2026-92757

CVE-2026-92757 debrief based on CVE Program and NVD records. Applications built on MongoDB Entity Framework Core Provider that place a database name in the connection string may inadvertently disable field level encryption. This could potentially expose sensitive data. Defenders and developers should assess usage and database connection strings to verify field level encryption configuration and prevent po [truncated]

MEDIUM MongoDB Inc. CVE published 2026-09-17

CVE-2026-92756

CVE-2026-92756 debrief based on MongoDB Entity Framework Core Provider CVE description. Applications built on MongoDB Entity Framework Core Provider may store protected fields unencrypted due to combined encryption settings. This vulnerability affects applications that use both independent encryption settings and the provider's encryption settings, potentially leading to silent loss of TLS and schema-map [truncated]

HIGH MongoDB, Inc. CVE published 2026-07-22

CVE-2026-13058

CVE-2026-13058 is a high-severity vulnerability that allows an authenticated user with basic write privileges to cause the mongod process to terminate abnormally. This is achieved by sending a crafted transaction command with an incomplete set of required fields, resulting in a fatal internal invariant failure and denial of service. The vulnerability affects MongoDB-like systems and has a CVSS score of 7. [truncated]

MEDIUM MongoDB, Inc. CVE published 2026-07-22

CVE-2026-13057

An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation stages use internal routing that is normally populated only by the trusted router during sharded search planning. Due to insufficient input validation, an authenticated client can supply these fields directly. This vulnerability h [truncated]

MEDIUM MongoDB, Inc. CVE published 2026-05-20

CVE-2026-9101

CVE-2026-9101 describes a prototype pollution flaw in CSV parsing during import. Under specific user actions, the issue can cause untrusted file paths — not arbitrary arguments — to reach shell.openExternal, which can result in one-click command execution in the affected desktop workflow.

MEDIUM MongoDB, Inc. CVE published 2026-05-20

CVE-2026-9100

CVE-2026-9100 describes a flaw in the MongoDB C Driver’s legacy GridFS API where malformed file metadata from the database is not validated adequately. If an application reads a crafted GridFS document through that legacy API, the result can be a denial of service crash (division-by-zero) or a silent memory disclosure via out-of-bounds read. NVD published the CVE on 2026-05-20 and listed the issue as Awai [truncated]

MEDIUM MongoDB Inc. CVE published 2026-05-14

CVE-2026-6811

A stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances. This issue arises when the source of these BSON documents is not MongoDB Server. The vulnerability has a CVSS score of 6 and is classified as MEDIUM severity. The affected versions are between 1.21.0 and 1.21.5 and between 2.1.0 and 2.1.8. Defender [truncated]

CRITICAL MongoDB, Inc. CVE published 2026-05-12

CVE-2026-8431

CVE-2026-8431: MongoDB Ops Manager Webhook Arbitrary Command Execution. This critical vulnerability affects MongoDB Ops Manager versions 7.0 and 8.0.22 and prior, allowing administrative users with access to configure webhooks to execute arbitrary commands via specific FreeMarker template syntax. The vulnerability has a high CVSS score of 9.4, indicating a severe risk of potential command execution, eleva [truncated]

HIGH MongoDB Inc. CVE published 2026-05-06

CVE-2026-6691

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI. The vulnerability has a CVSS score of 8.6 and is classified as HIGH severity. Affected users should review and [truncated]