<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>MongoDB CVEs · CVE Brief</title>
    <link>https://cvebrief.com/archive/cves/vendor/mongodb/</link>
    <atom:link href="https://cvebrief.com/feeds/vendor/mongodb.xml" rel="self" type="application/rss+xml"/>
    <description>High and critical MongoDB vulnerabilities covered by CVE Brief, with independent analyst commentary.</description>
    <language>en-us</language>
    <lastBuildDate>Sun, 20 Sep 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-93758 · CVSS 8.1 · Mongoid</title>
      <link>https://cvebrief.com/cve/cve-2026-93758/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-93758</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Sun, 20 Sep 2026 12:00:00 GMT</pubDate>
      <description>An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-93760 · CVSS 8.2 · Mongoid</title>
      <link>https://cvebrief.com/cve/cve-2026-93760/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-93760</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Sun, 20 Sep 2026 12:00:00 GMT</pubDate>
      <description>Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-93759 · CVSS 8.6 · Mongoid</title>
      <link>https://cvebrief.com/cve/cve-2026-93759/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-93759</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Sat, 19 Sep 2026 12:00:00 GMT</pubDate>
      <description>Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-88023 · CVSS 8.3 · MongoDB PHP Library</title>
      <link>https://cvebrief.com/cve/cve-2026-88023/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-88023</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
      <description>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-88024 · CVSS 8.3 · Rust Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-88024/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-88024</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
      <description>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. Fix documented: 3.9.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-88025 · CVSS 8.3 · C# Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-88025/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-88025</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
      <description>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-88029 · CVSS 8.3 · Python Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-88029/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-88029</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
      <description>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. Fix documented: 4.18.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-88030 · CVSS 8.3 · Ruby Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-88030/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-88030</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
      <description>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-88033 · CVSS 8.3 · Java Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-88033/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-88033</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
      <description>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. Fix documented: 5.11.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-88034 · CVSS 8.3 · C++ Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-88034/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-88034</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
      <description>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. Fix documented: 4.5.3 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-88036 · CVSS 8.3 · C Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-88036/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-88036</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
      <description>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. Fix documented: 1.30.10 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-77586 · CVSS 8.0 · BI Connector</title>
      <link>https://cvebrief.com/cve/cve-2026-77586/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-77586</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Sun, 30 Aug 2026 12:00:00 GMT</pubDate>
      <description>In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. Fix documented: 2.14.31 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-81490 · CVSS 7.7 · BI Connector</title>
      <link>https://cvebrief.com/cve/cve-2026-81490/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-81490</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Sun, 30 Aug 2026 12:00:00 GMT</pubDate>
      <description>A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. Fix documented: 2.14.31 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-81517 · CVSS 7.5 · BI Connector</title>
      <link>https://cvebrief.com/cve/cve-2026-81517/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-81517</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Sun, 30 Aug 2026 12:00:00 GMT</pubDate>
      <description>An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. Fix documented: 2.14.31 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-81518 · CVSS 7.5 · BI Connector</title>
      <link>https://cvebrief.com/cve/cve-2026-81518/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-81518</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Sun, 30 Aug 2026 12:00:00 GMT</pubDate>
      <description>When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. Fix documented: 2.14.31 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-81520 · CVSS 7.5 · BI Connector</title>
      <link>https://cvebrief.com/cve/cve-2026-81520/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-81520</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Sun, 30 Aug 2026 12:00:00 GMT</pubDate>
      <description>A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Fix documented: 2.14.31 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-81532 · CVSS 8.8 · BI Connector ODBC Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-81532/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-81532</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Sat, 29 Aug 2026 12:00:00 GMT</pubDate>
      <description>A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Fix documented: 1.4.10 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-81522 · CVSS 8.1 · C++ Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-81522/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-81522</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>A weakness in the MongoDB C++ Driver&apos;s handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. Fix documented: 4.5.1 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-81525 · CVSS 8.1 · PHP Library</title>
      <link>https://cvebrief.com/cve/cve-2026-81525/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-81525</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. Fix documented: 1.21.4 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-19001 · CVSS 9.8 · BI Connector ODBC Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-19001/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-19001</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate>
      <description>The MongoDB BI Connector ODBC Driver is susceptible to a buffer overflow during metadata retrieval, which may lead to process termination or arbitrary code execution. Fix documented: 1.4.9 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-18691 · CVSS 8.8 · MongoDB Server</title>
      <link>https://cvebrief.com/cve/cve-2026-18691/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-18691</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Wed, 12 Aug 2026 12:00:00 GMT</pubDate>
      <description>An issue in MongoDB Server&apos;s intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another Fix documented: 8.3.8 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-18692 · CVSS 8.8 · MongoDB Server</title>
      <link>https://cvebrief.com/cve/cve-2026-18692/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-18692</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Wed, 12 Aug 2026 12:00:00 GMT</pubDate>
      <description>An issue in MongoDB Server&apos;s handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed Fix documented: 8.3.8 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13059 · CVSS 8.1 · MongoDB Server</title>
      <link>https://cvebrief.com/cve/cve-2026-13059/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-13059</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 24 Jul 2026 12:00:00 GMT</pubDate>
      <description>An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters Fix documented: 7.0.39 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13072 · CVSS 8.1 · MongoDB Server</title>
      <link>https://cvebrief.com/cve/cve-2026-13072/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-13072</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 24 Jul 2026 12:00:00 GMT</pubDate>
      <description>When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior Fix documented: 7.0.39 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-13078 · CVSS 7.7 · MongoDB Server</title>
      <link>https://cvebrief.com/cve/cve-2026-13078/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-13078</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 24 Jul 2026 12:00:00 GMT</pubDate>
      <description>A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process&apos;s privileges Fix documented: 7.0.39 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-14881 · CVSS 7.8 · MongoDB Compass</title>
      <link>https://cvebrief.com/cve/cve-2026-14881/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-14881</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 24 Jul 2026 12:00:00 GMT</pubDate>
      <description>When importing connections in Compass it is possible to override some connection options that are otherwise can&apos;t be changed via connection form Fix documented: 1.49.7 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-11933 · CVSS 8.8 · MongoDB</title>
      <link>https://cvebrief.com/cve/cve-2026-11933/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-11933</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Fri, 12 Jun 2026 12:00:00 GMT</pubDate>
      <description>A use-after-free vulnerability exists in MongoDB Server&apos;s server-side JavaScript engine when converting BSON documents to JavaScript arrays Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-8053 · CVSS 8.8 · MongoDB Server</title>
      <link>https://cvebrief.com/cve/cve-2026-8053/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-8053</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Thu, 14 May 2026 12:00:00 GMT</pubDate>
      <description>An issue in MongoDB Server&apos;s time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process Fix documented: 5.0.33 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-6691 · CVSS 7.8 · MongoDB C Driver</title>
      <link>https://cvebrief.com/cve/cve-2026-6691/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-6691</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Thu, 07 May 2026 12:00:00 GMT</pubDate>
      <description>The MongoDB C Driver&apos;s Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-4148 · CVSS 8.8 · MongoDB Server</title>
      <link>https://cvebrief.com/cve/cve-2026-4148/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2026-4148</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Wed, 18 Mar 2026 12:00:00 GMT</pubDate>
      <description>A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline Fix documented: 8.2.6 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-14847 · CVSS 7.5 · actively exploited (CISA KEV) · MongoDB Server</title>
      <link>https://cvebrief.com/cve/cve-2025-14847/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2025-14847</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Sat, 20 Dec 2025 12:00:00 GMT</pubDate>
      <description>Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client Fix documented: 8.2.3 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-11575 · CVSS 7.8 · Atlas SQL ODBC driver</title>
      <link>https://cvebrief.com/cve/cve-2025-11575/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2025-11575</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Thu, 23 Oct 2025 12:00:00 GMT</pubDate>
      <description>Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-12100 · CVSS 7.8 · BI Connector ODBC Driver</title>
      <link>https://cvebrief.com/cve/cve-2025-12100/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2025-12100</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Thu, 23 Oct 2025 12:00:00 GMT</pubDate>
      <description>Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-11695 · CVSS 8.0 · Rust Driver</title>
      <link>https://cvebrief.com/cve/cve-2025-11695/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2025-11695</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Mon, 13 Oct 2025 12:00:00 GMT</pubDate>
      <description>When tlsInsecure=False appears in a connection string, certificate validation is disabled Fix documented: v3.2.5 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-10491 · CVSS 7.8 · MongoDB Server</title>
      <link>https://cvebrief.com/cve/cve-2025-10491/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2025-10491</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Mon, 15 Sep 2025 12:00:00 GMT</pubDate>
      <description>The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB&apos;s process via DLL hijacking Fix documented: 6.0.25 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-6713 · CVSS 7.7 · MongoDB Server</title>
      <link>https://cvebrief.com/cve/cve-2025-6713/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-mongodb-CVE-2025-6713</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/mongodb.png" medium="image" type="image/png"/>
      <pubDate>Mon, 07 Jul 2025 12:00:00 GMT</pubDate>
      <description>An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server Fix documented: 6.0.22 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
  </channel>
</rss>
