Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MongoDB server — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in MongoDB server, with AI-generated Chinese analysis, references, and POCs.

This page serves as a comprehensive vulnerability aggregation hub for MongoDB Server, focusing on the Common Weakness Enumeration (CWE) classification system to organize and contextualize security flaws. It collects and catalogs reported security weaknesses affecting this specific database management system, covering incidents disclosed from the initial release of the software up to the present day, ensuring a complete historical perspective on its security posture. By aggregating data from multiple reliable sources, this resource allows users to track vendor advisories and official patches issued by MongoDB Inc., providing a clear timeline of remediation efforts and critical updates. Readers can use this page to understand the underlying nature of specific weakness classes, such as injection flaws or improper access controls, and how they manifest in MongoDB’s architecture. Additionally, the tool enables users to look up a product's vulnerability history, offering insights into recurring issues, severity trends, and the overall evolution of security practices within the MongoDB ecosystem. This centralized view simplifies the process of assessing risk for administrators and developers who rely on MongoDB for their data infrastructure, facilitating informed decisions regarding upgrades, mitigation strategies, and compliance requirements without the need to search across disparate security databases.

Vendor: MongoDB Inc.

CVE IDTitleCVSSSeverityPublished
CVE-2026-18712 Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections CWE-863 8.1 High2026-08-11
CVE-2026-18711 Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure CWE-416 7.1 High2026-08-11
CVE-2026-18709 Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency CWE-862 6.4 Medium2026-08-11
CVE-2026-18698 Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command CWE-863 5.4 Medium2026-08-11
CVE-2026-18690 Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections CWE-863 8.1 High2026-08-11
CVE-2026-18699 Improper Input Validation in MongoDB Query Planner Leads to Denial of Service CWE-476 6.5 Medium2026-08-11
CVE-2026-18691 Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure CWE-757 8.8 High2026-08-11
CVE-2026-18702 Improper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic Settings CWE-269 6.4 Medium2026-08-11
CVE-2026-18694 Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory Disclosure CWE-125 7.1 High2026-08-11
CVE-2026-18708 Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query Scopes CWE-94 6.4 Medium2026-08-11
CVE-2026-18696 Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections CWE-863 6.5 Medium2026-08-11
CVE-2026-18700 Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service CWE-416 6.5 Medium2026-08-11
CVE-2026-18701 Type Confusion in MongoDB Query Subsystem Leads to Denial of Service CWE-843 6.5 Medium2026-08-11
CVE-2026-18697 Improper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongos CWE-617 7.5 High2026-08-11
CVE-2026-18693 Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory Disclosure CWE-787 7.6 High2026-08-11
CVE-2026-18705 Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View Data CWE-807 6.5 Medium2026-08-11
CVE-2026-18704 Improper Authorization in MongoDB Aggregation Framework Allows Read-Only User to Perform Unauthorized Write Operations CWE-862 6.5 Medium2026-08-11
CVE-2026-18692 Use-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code Execution CWE-416 8.8 High2026-08-11
CVE-2026-18688 Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potential Memory Disclosure CWE-125 7.1 High2026-08-11
CVE-2026-18695 Improper Input Validation in MongoDB Timeseries Query Processing Leads to Denial of Service CWE-617 6.5 Medium2026-08-11
CVE-2026-18687 Improper Validation in MongoDB Queryable Encryption Maintenance Operation Leads to Denial of Service and Index Corruption CWE-191 7.1 High2026-08-11
CVE-2026-18706 Use-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of Service and Potential Remote Code Execution CWE-416 6.6 Medium2026-08-11
CVE-2026-18707 Improper Input Validation in MongoDB Aggregation Command Handling Leads to Denial of Service CWE-617 4.3 Medium2026-08-11
CVE-2026-18703 Improper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication Method CWE-863 4.2 Medium2026-08-11
CVE-2026-13055 Server crash via aggregation pipeline expression with compound wildcard index specification CWE-617 6.5 Medium2026-07-22
CVE-2026-13056 A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM CWE-1325 6.5 Medium2026-07-22
CVE-2026-13057 Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_META CWE-20 5.3 Medium2026-07-22
CVE-2026-13058 Transaction Command Insufficient Input Validation Leading to Process Termination CWE-617 7.1 High2026-07-22
CVE-2026-13059 Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass CWE-807 8.1 High2026-07-22
CVE-2026-9737 Find command with $meta sort can lead to crash CWE-617 6.5 Medium2026-07-22

All 146 known CVE vulnerabilities affecting MongoDB server with full Chinese analysis, references, and POCs where available.