- EPSS 0.25%
- Veröffentlicht 08.09.2026 16:12:18
- Zuletzt bearbeitet 16.09.2026 20:35:00
A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index lifecycle operations, a raw pointer to internal text index metadata may be dereference...
CVE-2026-82054
- EPSS 0.29%
- Veröffentlicht 08.09.2026 16:12:17
- Zuletzt bearbeitet 16.09.2026 20:40:15
A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limi...
CVE-2026-82055
- EPSS 0.29%
- Veröffentlicht 08.09.2026 16:12:17
- Zuletzt bearbeitet 16.09.2026 20:35:09
A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a specially crafted GeoJSON document is inserted into a collection with a 2dsphere index, an inconsistency in geo...
CVE-2026-82053
- EPSS 0.24%
- Veröffentlicht 08.09.2026 16:12:16
- Zuletzt bearbeitet 16.09.2026 20:40:31
A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an...
CVE-2026-82052
- EPSS 0.36%
- Veröffentlicht 08.09.2026 16:12:15
- Zuletzt bearbeitet 16.09.2026 20:40:42
The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the regex match can start in the middle of a multi-code-unit character, t...
CVE-2026-84967
- EPSS 0.16%
- Veröffentlicht 03.09.2026 15:18:02
- Zuletzt bearbeitet 09.09.2026 19:51:55
A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote una...
CVE-2026-18712
- EPSS 0.18%
- Veröffentlicht 11.08.2026 18:49:28
- Zuletzt bearbeitet 25.09.2026 15:28:14
An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This...
CVE-2026-18711
- EPSS 0.27%
- Veröffentlicht 11.08.2026 18:48:50
- Zuletzt bearbeitet 25.09.2026 15:35:43
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries against time-serie...
CVE-2026-18709
- EPSS 0.14%
- Veröffentlicht 11.08.2026 18:48:11
- Zuletzt bearbeitet 16.09.2026 15:19:45
An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-...
CVE-2026-18698
- EPSS 0.17%
- Veröffentlicht 11.08.2026 18:47:34
- Zuletzt bearbeitet 16.09.2026 15:17:51
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metad...