Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MongoDB Server — Vulnerabilities & Security Advisories 171

All 171 CVE vulnerabilities found in MongoDB Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for MongoDB Server, a NoSQL database system developed by MongoDB Inc. It collects critical flaws categorized by weakness type, such as remote code execution, privilege escalation, and denial-of-service issues, covering advisories published over the last several years. Readers can use this resource to track the vendor’s security advisories, understand specific weakness classes like injection or buffer overflow, and review the historical vulnerability landscape for this product. The data is organized to support security analysts, developers, and IT managers who need to assess risk exposure and monitor remediation trends without navigating through disparate sources.

Vendor: MongoDB Inc.

CVE ID Title CVSS Severity Published
CVE-2026-89099 Race Condition in MongoDB Server Document Value Layer Leads to Memory Corruption CWE-362 7.5 High 2026-09-11
CVE-2026-82076 Integer Overflow in Query Planner Leads to Unbounded Memory Allocation and Denial of Service in MongoDB Server CWE-190 6.5 Medium 2026-09-08
CVE-2026-82075 Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Service CWE-770 7.5 High 2026-09-08
CVE-2026-82074 Incorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection Data CWE-863 6.5 Medium 2026-09-08
CVE-2026-82071 Insufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds Write CWE-787 8.1 High 2026-09-08
CVE-2026-82073 Improper Validation in MongoDB Server Aggregation Framework Allows Authorization Bypass and Unauthorized Collection Access with Atlas Search CWE-863 6.5 Medium 2026-09-08
CVE-2026-82070 Insufficiently Protected Credentials in MongoDB Server Diagnostic Reporting Interface CWE-522 6.5 Medium 2026-09-08
CVE-2026-82068 Persistent Fatal Assertion Crash in MongoDB Server via Crafted Retryable Write Commands Leads to Denial of Service CWE-617 6.5 Medium 2026-09-08
CVE-2026-82069 Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster Router CWE-212 2.7 Low 2026-09-08
CVE-2026-82067 Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup CWE-178 8.1 High 2026-09-08
CVE-2026-82066 Heap Out-of-Bounds Read in MongoDB Server Query Planning Component CWE-125 4.3 Medium 2026-09-08
CVE-2026-82064 Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members CWE-617 7.5 High 2026-09-08
CVE-2026-82065 Insufficient Validation of Storage Configuration Options in MongoDB Server Leads to Persistent Denial of Service via Corrupted Metadata CWE-617 6.5 Medium 2026-09-08
CVE-2026-82063 Use-After-Free in MongoDB Server Cursor Management Component Leads to Denial of Service CWE-416 5.3 Medium 2026-09-08
CVE-2026-82062 Improper Authorization in MongoDB Server applyOps Command Allows Writes to Arbitrary Internal Storage Tables via Feature Gate Bypass CWE-863 5.5 Medium 2026-09-08
CVE-2026-82061 Use-After-Free in MongoDB Server Query Execution Memory Tracking Subsystem Leads to Denial of Service CWE-416 8.1 High 2026-09-08
CVE-2026-82060 Insufficient Validation of Shard Key Values in MongoDB Server Leads to Query Operator Injection in Change Stream Post-Image Lookups CWE-943 5.4 Medium 2026-09-08
CVE-2026-82059 Improper Access Restriction of Internal Aggregation Expression in MongoDB Server Leads to Assertion Failure and Denial of Service CWE-617 5.3 Medium 2026-09-08
CVE-2026-82058 Unhandled Exception in MongoDB Server JSON Schema Validation Error Generation Leads to Denial of Service CWE-248 6.5 Medium 2026-09-08
CVE-2026-82057 Type Confusion in MongoDB Server WiredTiger Storage Engine via Custom Collection Configuration Leads to Persistent Denial of Service CWE-843 6.5 Medium 2026-09-08
CVE-2026-82056 Race Condition in MongoDB Server Text Index Query Parsing Leads to Heap Use-After-Free and Denial of Service CWE-416 5.3 Medium 2026-09-08
CVE-2026-82055 Null Pointer Dereference in MongoDB Server 2dsphere Index Key Generation Leads to Denial of Service CWE-476 6.5 Medium 2026-09-08
CVE-2026-82054 Uncontrolled Resource Consumption in MongoDB Server JSON Pointer Parser Leads to Denial of Service CWE-770 6.5 Medium 2026-09-08
CVE-2026-82052 $regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 chars CWE-617 6.5 Medium 2026-09-08
CVE-2026-82053 Improper Session Handling in MongoDB Server LDAP Authorization Integration Leads to Incorrect Role Assignment CWE-863 8.1 High 2026-09-08
CVE-2026-18712 Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections CWE-863 8.1 High 2026-08-11
CVE-2026-18711 Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure CWE-416 7.1 High 2026-08-11
CVE-2026-18709 Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency CWE-862 6.4 Medium 2026-08-11
CVE-2026-18698 Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command CWE-863 5.4 Medium 2026-08-11
CVE-2026-18690 Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections CWE-863 8.1 High 2026-08-11

All 171 known CVE vulnerabilities affecting MongoDB Server with full Chinese analysis, references, and POCs where available.