| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Mongodb products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-8063 | An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When resolving a view, the server inspects the aggregation pipeline to determine whet... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-6915 | An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect ho... | 4.3 | 99 | Neutral | No | Yes |
| CVE-2026-6914 | Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server. This issue affects all MongoDB Server v8.2 versions, all MongoDB Serve... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-6231 | The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequ... | 7.5 | 471 | Neutral | No | Yes |
| CVE-2026-5170 | A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during the limited and unpredictable window when the cluster is being promoted from a ... | 5.3 | 117 | Neutral | No | Yes |
| CVE-2026-4359 | A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver. | 3.7 | 102 | Neutral | No | Yes |
| CVE-2026-4358 | A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when a... | 7.5 | 379 | Neutral | No | Yes |
| CVE-2026-4148 | A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline. | 8.8 | 673 | Neutral | No | Yes |
| CVE-2026-4147 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command. | 4.3 | 99 | Neutral | No | Yes |
| CVE-2026-25613 | An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index. | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-25610 | An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints. | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-25609 | Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only. | 4.3 | 163 | Neutral | No | Yes |
| CVE-2026-1850 | Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash. | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-1849 | MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodical... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-1848 | Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connections exceeds available resources. This only applies... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-1847 | Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the oplog from the primary. This could stall replication inside the replica set leadi... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2025-7259 | An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This issue can only be triggered by authorized users and... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2025-6714 | MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue a... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2025-6713 | An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may l... | 6.5 | 354 | Neutral | Yes | Yes |
| CVE-2025-6712 | MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to inefficiencies in memory management related to internal op... | 6.5 | 209 | Neutral | No | Yes |