mongodb
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting mongodb.
- CVE-2026-14881Compass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flow7.8
- CVE-2026-13055Server crash via aggregation pipeline expression with compound wildcard index specification6.5
- CVE-2026-13056A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM6.5
- CVE-2026-13057Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_META5.3
- CVE-2026-13058Transaction Command Insufficient Input Validation Leading to Process Termination6.5
- CVE-2026-13059Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass8.1
- CVE-2026-9737Find command with $meta sort can lead to crash6.5
- CVE-2026-13060$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access6.5
- CVE-2026-13061Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage4.3
- CVE-2026-13062MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters6.5
- CVE-2026-13063libmongocrypt Improper Input Validation Leading to Process Termination4.3
- CVE-2026-13064MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service6.5
- CVE-2026-13065MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination6.5
- CVE-2026-13066Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure6.5
- CVE-2026-13067tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket6.3