PatchSiren

MongoDB CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM MongoDB CVE published 2026-08-28

CVE-2026-76798

The MongoSQL Transition Readiness Tool is vulnerable to a report generation issue. A user able to issue queries through the BI Connector can influence log content so that markup supplied in a query is interpreted by the browser when an operator later generates and opens the report. This may disclose other users' logged query text and user names to an external party or present misleading content to the operator.

MEDIUM MongoDB CVE published 2026-08-28

CVE-2026-76797

CVE-2026-76797 debrief based on CVE Program and NVD records. The MongoSQL Transition Readiness Tool is vulnerable to CSV formula injection, allowing a user with write privileges to choose a namespace name that is later evaluated as a formula when an operator opens the generated report in a spreadsheet application. This may result in unintended disclosure of report contents or execution of external content [truncated]

MEDIUM MongoDB CVE published 2026-08-28

CVE-2026-76794

The MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML, allowing a MongoDB user with write access to introduce crafted metadata that may cause script code to run when another user generates and opens the report, potentially exposing report contents or altering its display. This issue affects MongoDB users with write access who can introd [truncated]

LOW MongoDB CVE published 2026-08-27

CVE-2026-81523

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema selection, which may lead to limited disclosure or modification of information handled by the application. This issue affects MongoDB libmongocrypt deployments, and defenders shou [truncated]

MEDIUM MongoDB CVE published 2026-08-27

CVE-2026-75573

CVE-2026-75573 debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T17:19:59.120Z and has not been modified since then. This vulnerability affects MongoDB Connector for BI, particularly versions 2.12.0 up to 2.14.30. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key. Defen [truncated]

HIGH MongoDB CVE published 2026-08-27

CVE-2026-75159

A MongoDB BI Connector deployment with Kerberos authentication is vulnerable to termination by an unauthenticated client through a crafted authentication exchange that triggers a specific GSSAPI error-handling condition. This affects availability until the process restarts. The vulnerability can be triggered by an unauthenticated client, and defenders should verify exposure and prioritize remediation or c [truncated]

HIGH MongoDB CVE published 2026-08-12

CVE-2026-19004

A memory-safety issue in the MongoDB BI Connector ODBC Driver can occur when processing output parameters from a stored procedure, potentially leading to process termination, memory disclosure, or arbitrary code execution under certain conditions. This issue arises when connecting to an untrusted or impersonated database server that returns crafted metadata. Defenders and administrators responsible for Mo [truncated]

HIGH MongoDB CVE published 2026-08-12

CVE-2026-19002

A missing bounds check in the MongoDB BI Connector ODBC Driver can lead to an out-of-bounds write, potentially causing the client application to terminate abnormally or execute unintended code. This issue requires control over the server the driver connects to or the ability to respond in its place to return malformed metadata. The vulnerability has a high CVSS score of 8.8, indicating a significant risk. [truncated]

HIGH MongoDB CVE published 2026-08-11

CVE-2026-18710

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T22:17:20.113Z and has not been modified since then. The issue involves a MongoDB driver component that writes sensitive configuration information, including credentials, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operat [truncated]

HIGH MongoDB CVE published 2026-08-11

CVE-2026-18712

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T19:17:29.360Z and has not been modified since then. This issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collectio [truncated]

MEDIUM MongoDB CVE published 2026-08-11

CVE-2026-18709

An authenticated user with direct network access to a shard could improperly commit or abort an in-progress prepared transaction in MongoDB Server, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency, cluster clock corruption, and violation of transaction atomicity guarantees. The issue affects MongoDB Server, potentially impacting data integrity an [truncated]

HIGH MongoDB CVE published 2026-08-11

CVE-2026-18704

An authenticated user with only read privileges could perform write operations against collections they should not modify due to an internal-use aggregation stage being reachable without proper authorization. This issue in MongoDB Server's aggregation framework allows unauthorized modifications, potentially leading to data integrity risks. Affected deployments should review aggregation stage access contro [truncated]

LOW MongoDB CVE published 2026-08-11

CVE-2026-18703

The CVE-2026-18703 record describes a low-severity issue in MongoDB Server that could allow a party with a valid client certificate and corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms. This issue was published on 2026-08-11T19:17:24.900Z and has not been modified [truncated]

MEDIUM MongoDB CVE published 2026-08-11

CVE-2026-18702

An authenticated user with limited database-scoped privileges in MongoDB Server could modify diagnostic logging settings server-wide, potentially obscuring unauthorized activity or degrading operational monitoring. This issue allows an authenticated user to modify diagnostic logging settings that affect the entire server rather than just the intended database, which could allow suppression of diagnostic l [truncated]

HIGH MongoDB CVE published 2026-08-11

CVE-2026-18701

CVE-2026-18701 is a denial-of-service vulnerability in MongoDB Server's query subsystem. An authenticated user with read privileges can cause the server process to terminate unexpectedly by submitting a specially formed query filter. This issue affects multiple versions of MongoDB Server, including 7.0.0 to 7.0.40, 8.0.0 to 8.0.29, 8.2.0 to 8.2.12, and 8.3.0 to 8.3.8, as well as some alpha versions of 9.0 [truncated]

MEDIUM MongoDB CVE published 2026-08-11

CVE-2026-18699

The CVE-2026-18699 issue in MongoDB Server's query planner allows an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, affecting connected clients and in-flight operations. MongoDB Server administrators should review the official CVE Pro [truncated]

MEDIUM MongoDB CVE published 2026-08-11

CVE-2026-18698

CVE-2026-18698 is a vulnerability in MongoDB Server that could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections. This may result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Adminis [truncated]

HIGH MongoDB CVE published 2026-08-11

CVE-2026-18697

A denial-of-service vulnerability exists in MongoDB Server's aggregation framework. An unauthenticated party can cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command, disrupting client connections routed through the affected mongos instance. This issue affects MongoDB Server versions 7.0.0 to 7.0.40, 8.0.0 to 8.0.29, 8.2.0 to 8.2.12, and 8.3.0 to 8 [truncated]

HIGH MongoDB CVE published 2026-08-11

CVE-2026-18696

An authenticated user with specific non-default privileges could perform certain data-definition operations against collections they do not have permission to manipulate due to an inconsistency in how the target collection is determined between the authorization check and the actual operation in MongoDB Server's applyOps command. This issue arises from a discrepancy in MongoDB Server's handling of the app [truncated]

HIGH MongoDB CVE published 2026-08-11

CVE-2026-18694

A vulnerability in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause a denial of service and potentially expose a limited amount of server process memory. This issue arises from improper validation of malformed geometry data, which can lead to server crashes and memory exposure. Defenders should assess their exposure, prioritize updates, and moni [truncated]

HIGH MongoDB CVE published 2026-08-11

CVE-2026-18690

The CVE-2026-18690 issue in MongoDB Server allows an authenticated user with a limited database-scoped role to perform actions against protected system collections that their privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization. MongoDB Server administrators and users with limited database-scoped roles should verify configu [truncated]

HIGH MongoDB CVE published 2026-08-11

CVE-2026-18688

An authenticated user could trigger an out-of-bounds memory read in MongoDB Server's aggregation framework by providing a specially formed numeric parameter, potentially causing a server crash and limited memory exposure. This issue affects MongoDB Server, a popular NoSQL database used for storing and managing large amounts of data. The vulnerability has a high severity score and requires immediate attent [truncated]

HIGH MongoDB CVE published 2026-06-12

CVE-2026-11933

CVE-2026-11933 is a use-after-free vulnerability in MongoDB Server's server-side JavaScript engine. An authenticated user with read privileges who can run server-side JavaScript can cause the server to access memory that has already been freed, potentially resulting in disclosure of information from the mongod process memory or a denial of service through a server crash.

HIGH MongoDB CVE published 2026-06-09

CVE-2026-9754

CVE-2026-9754 is a vulnerability affecting an unspecified product from an unknown vendor. An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity.

HIGH MongoDB CVE published 2026-06-09

CVE-2026-9753

The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.

HIGH MongoDB CVE published 2026-06-09

CVE-2026-9752

CVE-2026-9752 is a HIGH severity vulnerability with a CVSS score of 7.1. An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. This occurs because the guard that rejects strict-winding polygons does not inspect members of a GeometryCollection, allowing the unsafe path to b [truncated]

MEDIUM MongoDB CVE published 2026-06-09

CVE-2026-9751

CVE-2026-9751 is a medium-severity vulnerability in MongoDB. The ldapQueryPassword parameter, when set through the runtime setParameter command, logs the new password to the mongod.log file in plain text. This issue was published on [CVE.org](resourceLinkAnnotations:cve-org) on 2026-06-09 and has a CVSS score of 6.8.

HIGH MongoDB CVE published 2026-06-09

CVE-2026-9750

CVE-2026-9750 is a HIGH-severity vulnerability (CVSS Score: 7.1) affecting an unknown vendor and product. An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.

HIGH MongoDB CVE published 2026-06-09

CVE-2026-9749

CVE-2026-9749 is a HIGH severity vulnerability with a CVSS score of 7.1. The issue occurs when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer, the server reaches the code path where a full per-consumer buffer is detected but the internal [truncated]

HIGH MongoDB CVE published 2026-06-09

CVE-2026-9748

CVE-2026-9748 is a HIGH severity vulnerability in MongoDB. The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal 'skip this document' when an index stats conversion failed. However, PauseExecution is not a general-purpose skip mechanism but rather a TeeBuffer-internal signal used solely by $facet to coordinate its sub-pipelines. When this stage is placed before $facet in a pip [truncated]