MongoDB Compass 在用户从其数据库视图打开嵌入式的 MongoDB Shell 时,会对数据库名称进行插值处理而未进行适当的转义,从而将其插入到 Shell 的初始输入中。如果某用户在 Compass 所连接的目标服务器上具有创建数据库的权限,则在特定条件下,该用户可能使其构造的内容被作为 Shell 输入在 Compass 进程内执行,并继承该进程的权限。此漏洞利用要求 Compass 用户打开受影响数据库对应的 Shell。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96749 | 8.4 HIGH | Heap out-of-bounds write via signed size overflow in BSON document encoding |
| CVE-2026-96744 | 7.1 HIGH | Unauthorized cache lock takeover via expression injection in lock owner values in MongoDB |
| CVE-2026-96746 | 6.5 MEDIUM | Heap buffer overflow via mid-scan command list growth in client topology monitoring |
| CVE-2026-96748 | 6.5 MEDIUM | Connection redirection via percent-encoded delimiter injection in connection string hosts |
| CVE-2026-96745 | 5.6 MEDIUM | PHP object injection via unsuppressible __pclass class inference in command monitoring eve |
| CVE-2026-96747 | 5.0 MEDIUM | Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encrypt |
No comments yet