Search CVE reports


Toggle filters

31 – 40 of 205 results


CVE-2026-19503

Medium priority
Needs evaluation

MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-19502

Medium priority
Needs evaluation

MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-18888

Medium priority
Needs evaluation

The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text,...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-18712

Medium priority
Needs evaluation

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-18711

Medium priority
Needs evaluation

An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-18709

Medium priority
Needs evaluation

An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-18708

Medium priority
Needs evaluation

An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-18707

Medium priority
Needs evaluation

An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-18706

Medium priority
Needs evaluation

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-18705

Medium priority
Needs evaluation

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages