| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Mongodb products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-9754 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-9753 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyO... | 8.1 | 605 | Neutral | No | Yes |
| CVE-2026-9752 | An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-win... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-9751 | The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text. | 5.5 | 125 | Neutral | No | Yes |
| CVE-2026-9750 | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from ins... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-9749 | This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces en... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-9748 | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a general purpose skip mechanis... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-9747 | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-9746 | When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special privileges needed. The user mu... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-9743 | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on the same cursor, the server may derefer... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-9742 | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is ... | 5.9 | 155 | Neutral | No | Yes |
| CVE-2026-9741 | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields wi... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-9740 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain ne... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-9735 | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication paramet... | 5.5 | 125 | Neutral | No | Yes |
| CVE-2026-8336 | After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the ser... | 6.5 | 338 | Neutral | No | Yes |
| CVE-2026-8202 | Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilization... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-8201 | A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability requ... | 8.8 | 673 | Neutral | No | Yes |
| CVE-2026-8200 | When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted. This iss... | 5.3 | 124 | Neutral | No | Yes |
| CVE-2026-8199 | An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and m... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-8063 | An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When resolving a view, the server inspects the aggregation pipeline to determine whet... | 6.5 | 209 | Neutral | No | Yes |