VulnSea

mongodb has 117 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 111 in the last 90 days against 5 in the 90 before. The busiest recent month was September 2026 with 71. The median CVSS is 6.5 (medium), with 3 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-943 (17) and CWE-617 (10). Most affected products: mongodb (50), c_driver (9), mongoid (8).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
111 prev 5

Products

  • mongodb 50
  • c_driver 9
  • mongoid 8
  • bi_connector_odbc_driver 7
  • Laravel MongoDB (PHP) 4
  • Python Driver 4
117
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

mongodb vulnerabilities

CVEs affecting mongodb, newest first. Open any entry for full detail, references, and exploit status.

117 CVEsRSS

CVE-2026-18706Medium· 6.6
1mo ago

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. …

▾ Sunlitmongodb · mongodbEPSS 0.47%via NVD
CVE-2026-18705Medium· 6.5
1mo ago

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficie…

▾ Sunlitmongodb · mongodbEPSS 0.36%via NVD
CVE-2026-18704Medium· 6.5
1mo ago

An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify

An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation …

▾ Sunlitmongodb · mongodbEPSS 0.20%via NVD
CVE-2026-18703Medium· 4.2
1mo ago

An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to rest…

An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to rest…

▾ Sunlitmongodb · mongodbEPSS 0.14%via NVD
CVE-2026-18702Medium· 6.4
1mo ago

An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database

An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppressio…

▾ Sunlitmongodb · mongodbEPSS 0.27%via NVD
CVE-2026-18701Medium· 6.5
1mo ago

An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter

An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of ser…

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18700Medium· 6.5
1mo ago

An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a coll…

An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a coll…

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18699Medium· 6.5
1mo ago

An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index

An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. …

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18698Medium· 5.4
1mo ago

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of col…

▾ Sunlitmongodb · mongodbEPSS 0.24%via NVD
CVE-2026-18697High· 7.5
1mo ago

An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command

An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of s…

▾ Twilightmongodb · mongodbEPSS 0.44%via NVD
CVE-2026-18696Medium· 6.5
1mo ago

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do no…

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do no…

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18695Medium· 6.5
1mo ago

An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a …

An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a …

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18694High· 7.1
1mo ago

An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation

An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries agai…

▾ Twilightmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18693High· 7.6
1mo ago

An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions

An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert i…

▾ Twilightmongodb · mongodbEPSS 0.34%via NVD
CVE-2026-18692High· 8.8
1mo ago

An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed

An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations coul…

▾ Twilightmongodb · mongodbEPSS 0.57%via NVD
CVE-2026-18691High· 8.8
1mo ago

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, t…

▾ Twilightmongodb · mongodbEPSS 0.36%via NVD
CVE-2026-18690High· 8.1
1mo ago

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical sy…

▾ Twilightmongodb · mongodbEPSS 0.36%via NVD
CVE-2026-18688High· 7.1
1mo ago

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in …

▾ Twilightmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18687High· 7.1
1mo ago

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privil…

▾ Twilightmongodb · mongodbEPSS 0.23%via NVD
CVE-2026-13062Medium· 6.5
2mo ago

MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the m…

▾ SunlitMongoDB · MongoDB ServerEPSS 0.19%via CVEORG
CVE-2026-13060Medium· 6.5
2mo ago

$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access

An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and …

▾ SunlitMongoDB · MongoDB ServerEPSS 0.40%via CVEORG
CVE-2026-9101Medium· 4.3
4mo ago

Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.

Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.

▾ Sunlitmongodb · compassEPSS 0.45%via NVD
CVE-2026-9100Medium· 5.9
4mo ago

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to eithe…

▾ Sunlitmongodb · c_driverEPSS 0.30%via NVD
CVE-2026-8843Medium· 6.5
4mo ago

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server. A similar issue occurs when creating "querya…

▾ Sunlitmongodb · mongodbEPSS 0.42%via NVD
CVE-2026-6811Medium· 5.9
4mo ago

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

▾ Sunlitmongodb · php_driverEPSS 0.37%via NVD
CVE-2026-8431High· 7.2
4mo ago

An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.  This issue affects all MongoDB Ops Manager 7.0 versio…

An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.  This issue affects all MongoDB Ops Manager 7.0 versio…

▾ Twilightmongodb · ops_managerEPSS 0.70%via NVD
CVE-2021-20327Medium· 6.4
5y ago

A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate

A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result …

▾ Sunlitmongodb · mongodb_client_encryptionEPSS 0.20%via NVD
mongodb vulnerabilities (CVEs) — page 4 · VulnSea