Technology · MongoDB
MongoDB Server vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 62 vulnerabilities in MongoDB Server: 0 in the last 7 days and 39 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-82076, was published on 8 September 2026.
- Last 7 days
- 0
- Last 90 days
- 39
- Critical, all time
- 1
- Exploited in the wild
- 1
About MongoDB Server
A document-oriented NoSQL database program that uses JSON-like documents with optional schemas.
Latest MongoDB Server vulnerabilities
- CVE-2026-82076: MongoDB Server integer overflow in query plannermediumCVSS 6.5EPSS 0.4%
- CVE-2026-82069: MongoDB Server query statistics serialization information disclosurelowCVSS 2.7EPSS 0.4%
- CVE-2026-82068: MongoDB Server denial of service via retryable write command injectionmediumCVSS 6.5EPSS 0.4%
- CVE-2026-82064: MongoDB Server denial of service in read concern processinghighCVSS 7.5EPSS 0.5%
- CVE-2026-82060: MongoDB insufficient validation of shard key values in change streamsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-82058: MongoDB JSON Schema validation error generation denial of servicemediumCVSS 6.5EPSS 0.4%
- CVE-2026-82057: MongoDB readWrite privilege DoS via WiredTiger misconfigurationmediumCVSS 6.5EPSS 0.4%
- CVE-2026-82056: MongoDB heap use-after-free in text index query parsingmediumCVSS 5.3EPSS 0.3%
- CVE-2026-82055: MongoDB null pointer dereference in 2dsphere indexmediumCVSS 6.5EPSS 0.4%
- CVE-2026-82054: MongoDB server denial of service via $jsonSchema JSON Pointer parsermediumCVSS 6.5EPSS 0.4%
- CVE-2026-82053: MongoDB LDAP connection pooling privilege escalationhighCVSS 8.1EPSS 0.4%
- CVE-2026-82052: MongoDB $regexFindAll denial of service in aggregation pipelinemediumCVSS 6.5EPSS 0.5%
- CVE-2026-18704: MongoDB Server privilege escalation in aggregation frameworkmediumCVSS 6.5EPSS 0.2%
- CVE-2026-18691: MongoDB Server SASL mechanism downgrade in intra-cluster authenticationhighCVSS 8.8EPSS 0.4%
- CVE-2026-9737: MongoDB Server denial of service via meta expression in sort patternmediumCVSS 6.5
- CVE-2026-13078: MongoDB Server arbitrary file read in MozJS scripting enginehighCVSS 7.7
- CVE-2026-13077: MongoDB Server out-of-bounds read in BSON CodeWScope accessorshighCVSS 7.1
- CVE-2026-13076: MongoDB Server denial of service via memory exhaustion in aggregation frameworkmediumCVSS 6.5
- CVE-2026-13075: MongoDB Server denial of service via rankFusion and scoreFusion stagesmediumCVSS 6.5
- CVE-2026-13074: MongoDB Server denial of service via hello command exhaust modemediumCVSS 5.3
- CVE-2026-13073: MongoDB Server denial of service via crafted aggregation commandmediumCVSS 4.3
- CVE-2026-13072: MongoDB Server heap overflow in aggregation pipeline processinghighCVSS 8.1
- CVE-2026-13071: MongoDB Server use-after-free in $function aggregation operatormediumCVSS 6.5
- CVE-2026-13070: MongoDB Server denial of service via malformed OCSP responsemediumCVSS 5.3
- CVE-2026-13069: MongoDB Server denial of service in Queryable EncryptionmediumCVSS 6.5
Most severe MongoDB Server vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-14847: MongoDB Server uninitialized heap memory disclosure in Zlib headerscriticalexploited in the wildCVSS 8.7EPSS 68.9%
- CVE-2026-18691: MongoDB Server SASL mechanism downgrade in intra-cluster authenticationhighCVSS 8.8EPSS 0.4%
- CVE-2026-8053: MongoDB Server out-of-bounds write in time-series collectionshighCVSS 8.8EPSS 0.1%
- CVE-2026-11933: MongoDB Server use-after-free in server-side JavaScript enginehighCVSS 8.8
- CVE-2026-82053: MongoDB LDAP connection pooling privilege escalationhighCVSS 8.1EPSS 0.4%
- CVE-2026-13072: MongoDB Server heap overflow in aggregation pipeline processinghighCVSS 8.1
- CVE-2026-13059: MongoDB Server authorization bypass in query-level access controlshighCVSS 8.1
- CVE-2026-9753: MongoDB Server out-of-bounds read in $_internalApplyOplogUpdatehighCVSS 8.1
- CVE-2026-13078: MongoDB Server arbitrary file read in MozJS scripting enginehighCVSS 7.7
- CVE-2026-82064: MongoDB Server denial of service in read concern processinghighCVSS 7.5EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 25 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 12 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/mongodb-server.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "MongoDB Server vulnerabilities", https://junglewise.ai/threats/technologies/mongodb-server, 26 September 2026.