Mongodb
This hub aggregates every CVE we track for Mongodb, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
170
CVEs tracked
3
Critical
44
High
1
In CISA KEV
Severity distribution
MEDIUM120HIGH44LOW3CRITICAL3
Monthly trend
1
1
1
0
0
0
2
4
0
4
5
0
4
2
5
2
0
9
4
2
8
15
25
24
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Mongodb.
- CVE-2026-18712Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections8.1
- CVE-2026-18711Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure7.1
- CVE-2026-18709Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency6.4
- CVE-2026-18698Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command5.4
- CVE-2026-18690Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections8.1
- CVE-2026-18699Improper Input Validation in MongoDB Query Planner Leads to Denial of Service6.5
- CVE-2026-18691Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure8.8
- CVE-2026-18702Improper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic Settings6.4
- CVE-2026-18694Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory Disclosure7.1
- CVE-2026-18708Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query Scopes6.4
- CVE-2026-18696Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections6.5
- CVE-2026-18700Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service6.5
- CVE-2026-18701Type Confusion in MongoDB Query Subsystem Leads to Denial of Service6.5
- CVE-2026-18697Improper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongos7.5
- CVE-2026-18693Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory Disclosure7.6
Product normalization is registry-driven with AI assist and human review. How it works