MongoDB Server

26 known vulnerabilities in MongoDB Server, 1 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2025-14847 CVSS 8.7 high · actively exploited MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

Latest vulnerabilities

  • CVE-2026-89099 CVSS 7.7 high A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory…
  • CVE-2026-82076 CVSS 7.1 high An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level…
  • CVE-2026-82075 CVSS 8.7 high An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client…
  • CVE-2026-82074 CVSS 7.1 high MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal…
  • CVE-2026-82073 CVSS 7.1 high A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass…
  • CVE-2026-82071 CVSS 7.2 high Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to…
  • CVE-2026-82070 CVSS 7.1 high A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access…
  • CVE-2026-82069 CVSS 5.1 medium A security issue in MongoDB Server's query statistics serialization on the router allows users with monitoring privileges to access…
  • CVE-2026-82068 CVSS 7.1 high A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by…
  • CVE-2026-82067 CVSS 9.2 critical Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to…
  • CVE-2026-82066 CVSS 5.3 medium A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database…
  • CVE-2026-82065 CVSS 7.1 high A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges…
  • CVE-2026-82064 CVSS 8.7 high A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set…
  • CVE-2026-82063 CVSS 6.0 medium A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of…
  • CVE-2026-82062 CVSS 7.0 high A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled feature gate in the…
  • CVE-2026-82061 CVSS 7.2 high A use-after-free security issue exists in the server's query execution memory tracking subsystem. An authenticated user with read…
  • CVE-2026-82060 CVSS 2.3 low In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with…
  • CVE-2026-82059 CVSS 6.0 medium An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being…
  • CVE-2026-82058 CVSS 7.1 high A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the…
  • CVE-2026-82057 CVSS 7.1 high A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process. By…
  • CVE-2026-82056 CVSS 6.0 medium A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under…
  • CVE-2026-82055 CVSS 7.1 high A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a…
  • CVE-2026-82054 CVSS 7.1 high A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command…
  • CVE-2026-82053 CVSS 7.6 high A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication…
  • CVE-2026-82052 CVSS 7.1 high The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server…
  • CVE-2025-14847 CVSS 8.7 high · actively exploited MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability