{"schema_version":1,"title":"MongoDB Server vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 62 vulnerabilities in MongoDB Server: 0 in the last 7 days and 39 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-82076, was published on 8 September 2026.","url":"https://junglewise.ai/threats/technologies/mongodb-server","json_url":"https://junglewise.ai/threats/technologies/mongodb-server.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/mongodb-server","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":13,"all_time":62,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":12,"last_90_days":39,"last_365_days":62},"latest":[{"cve":"CVE-2026-82076","cvss":6.5,"epss":0.0041,"slug":"cve-2026-82076-mongodb-server-integer-overflow-in-query-planner","title":"MongoDB Server integer overflow in query planner","severity":"medium","exploited":false,"published_at":"2026-09-08T17:18:36.667+00:00","url":"https://junglewise.ai/threats/cve-2026-82076-mongodb-server-integer-overflow-in-query-planner"},{"cve":"CVE-2026-82069","cvss":2.7,"epss":0.0041,"slug":"cve-2026-82069-mongodb-server-query-statistics-serialization-information","title":"MongoDB Server query statistics serialization information disclosure","severity":"low","exploited":false,"published_at":"2026-09-08T17:18:35.877+00:00","url":"https://junglewise.ai/threats/cve-2026-82069-mongodb-server-query-statistics-serialization-information"},{"cve":"CVE-2026-82068","cvss":6.5,"epss":0.004,"slug":"cve-2026-82068-mongodb-server-denial-of-service-via-retryable-write-command","title":"MongoDB Server denial of service via retryable write command injection","severity":"medium","exploited":false,"published_at":"2026-09-08T17:18:35.75+00:00","url":"https://junglewise.ai/threats/cve-2026-82068-mongodb-server-denial-of-service-via-retryable-write-command"},{"cve":"CVE-2026-82064","cvss":7.5,"epss":0.0052,"slug":"cve-2026-82064-mongodb-server-denial-of-service-in-read-concern-processing","title":"MongoDB Server denial of service in read concern processing","severity":"high","exploited":false,"published_at":"2026-09-08T17:18:35.233+00:00","url":"https://junglewise.ai/threats/cve-2026-82064-mongodb-server-denial-of-service-in-read-concern-processing"},{"cve":"CVE-2026-82060","cvss":5.4,"epss":0.0032,"slug":"cve-2026-82060-mongodb-insufficient-validation-of-shard-key-values-in-change","title":"MongoDB insufficient validation of shard key values in change streams","severity":"medium","exploited":false,"published_at":"2026-09-08T17:18:34.7+00:00","url":"https://junglewise.ai/threats/cve-2026-82060-mongodb-insufficient-validation-of-shard-key-values-in-change"},{"cve":"CVE-2026-82058","cvss":6.5,"epss":0.004,"slug":"cve-2026-82058-mongodb-json-schema-validation-error-generation-denial-of-service","title":"MongoDB JSON Schema validation error generation denial of service","severity":"medium","exploited":false,"published_at":"2026-09-08T17:18:34.427+00:00","url":"https://junglewise.ai/threats/cve-2026-82058-mongodb-json-schema-validation-error-generation-denial-of-service"},{"cve":"CVE-2026-82057","cvss":6.5,"epss":0.0042,"slug":"cve-2026-82057-mongodb-readwrite-privilege-dos-via-wiredtiger-misconfiguration","title":"MongoDB readWrite privilege DoS via WiredTiger misconfiguration","severity":"medium","exploited":false,"published_at":"2026-09-08T17:18:34.287+00:00","url":"https://junglewise.ai/threats/cve-2026-82057-mongodb-readwrite-privilege-dos-via-wiredtiger-misconfiguration"},{"cve":"CVE-2026-82056","cvss":5.3,"epss":0.0033,"slug":"cve-2026-82056-mongodb-heap-use-after-free-in-text-index-query-parsing","title":"MongoDB heap use-after-free in text index query parsing","severity":"medium","exploited":false,"published_at":"2026-09-08T17:18:33.57+00:00","url":"https://junglewise.ai/threats/cve-2026-82056-mongodb-heap-use-after-free-in-text-index-query-parsing"},{"cve":"CVE-2026-82055","cvss":6.5,"epss":0.004,"slug":"cve-2026-82055-mongodb-null-pointer-dereference-in-2dsphere-index","title":"MongoDB null pointer dereference in 2dsphere index","severity":"medium","exploited":false,"published_at":"2026-09-08T17:18:33.41+00:00","url":"https://junglewise.ai/threats/cve-2026-82055-mongodb-null-pointer-dereference-in-2dsphere-index"},{"cve":"CVE-2026-82054","cvss":6.5,"epss":0.004,"slug":"cve-2026-82054-mongodb-server-denial-of-service-via-jsonschema-json-pointer","title":"MongoDB server denial of service via $jsonSchema JSON Pointer parser","severity":"medium","exploited":false,"published_at":"2026-09-08T17:18:33.28+00:00","url":"https://junglewise.ai/threats/cve-2026-82054-mongodb-server-denial-of-service-via-jsonschema-json-pointer"},{"cve":"CVE-2026-82053","cvss":8.1,"epss":0.0041,"slug":"cve-2026-82053-mongodb-ldap-connection-pooling-privilege-escalation","title":"MongoDB LDAP connection pooling privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-08T17:18:33.143+00:00","url":"https://junglewise.ai/threats/cve-2026-82053-mongodb-ldap-connection-pooling-privilege-escalation"},{"cve":"CVE-2026-82052","cvss":6.5,"epss":0.005,"slug":"cve-2026-82052-mongodb-regexfindall-denial-of-service-in-aggregation-pipeline","title":"MongoDB $regexFindAll denial of service in aggregation pipeline","severity":"medium","exploited":false,"published_at":"2026-09-08T17:18:32.987+00:00","url":"https://junglewise.ai/threats/cve-2026-82052-mongodb-regexfindall-denial-of-service-in-aggregation-pipeline"},{"cve":"CVE-2026-18704","cvss":6.5,"epss":0.002,"slug":"cve-2026-18704-mongodb-server-privilege-escalation-in-aggregation-framework","title":"MongoDB Server privilege escalation in aggregation framework","severity":"medium","exploited":false,"published_at":"2026-08-11T19:17:25.05+00:00","url":"https://junglewise.ai/threats/cve-2026-18704-mongodb-server-privilege-escalation-in-aggregation-framework"},{"cve":"CVE-2026-18691","cvss":8.8,"epss":0.0036,"slug":"cve-2026-18691-mongodb-server-sasl-mechanism-downgrade-in-intra-cluster","title":"MongoDB Server SASL mechanism downgrade in intra-cluster authentication","severity":"high","exploited":false,"published_at":"2026-08-11T19:17:22.903+00:00","url":"https://junglewise.ai/threats/cve-2026-18691-mongodb-server-sasl-mechanism-downgrade-in-intra-cluster"},{"cve":"CVE-2026-9737","cvss":6.5,"slug":"cve-2026-9737-mongodb-server-denial-of-service-via-meta-expression-in-sort","title":"MongoDB Server denial of service via meta expression in sort pattern","severity":"medium","exploited":false,"published_at":"2026-07-22T20:17:09.863+00:00","url":"https://junglewise.ai/threats/cve-2026-9737-mongodb-server-denial-of-service-via-meta-expression-in-sort"},{"cve":"CVE-2026-13078","cvss":7.7,"slug":"cve-2026-13078-mongodb-server-arbitrary-file-read-in-mozjs-scripting-engine","title":"MongoDB Server arbitrary file read in MozJS scripting engine","severity":"high","exploited":false,"published_at":"2026-07-22T20:16:46.65+00:00","url":"https://junglewise.ai/threats/cve-2026-13078-mongodb-server-arbitrary-file-read-in-mozjs-scripting-engine"},{"cve":"CVE-2026-13077","cvss":7.1,"slug":"cve-2026-13077-mongodb-server-out-of-bounds-read-in-bson-codewscope-accessors","title":"MongoDB Server out-of-bounds read in BSON CodeWScope accessors","severity":"high","exploited":false,"published_at":"2026-07-22T20:16:46.517+00:00","url":"https://junglewise.ai/threats/cve-2026-13077-mongodb-server-out-of-bounds-read-in-bson-codewscope-accessors"},{"cve":"CVE-2026-13076","cvss":6.5,"slug":"cve-2026-13076-mongodb-server-denial-of-service-via-memory-exhaustion-in","title":"MongoDB Server denial of service via memory exhaustion in aggregation framework","severity":"medium","exploited":false,"published_at":"2026-07-22T20:16:46.367+00:00","url":"https://junglewise.ai/threats/cve-2026-13076-mongodb-server-denial-of-service-via-memory-exhaustion-in"},{"cve":"CVE-2026-13075","cvss":6.5,"slug":"cve-2026-13075-mongodb-server-denial-of-service-via-rankfusion-and-scorefusion","title":"MongoDB Server denial of service via rankFusion and scoreFusion stages","severity":"medium","exploited":false,"published_at":"2026-07-22T20:16:46.213+00:00","url":"https://junglewise.ai/threats/cve-2026-13075-mongodb-server-denial-of-service-via-rankfusion-and-scorefusion"},{"cve":"CVE-2026-13074","cvss":5.3,"slug":"cve-2026-13074-mongodb-server-denial-of-service-via-hello-command-exhaust-mode","title":"MongoDB Server denial of service via hello command exhaust mode","severity":"medium","exploited":false,"published_at":"2026-07-22T20:16:46.057+00:00","url":"https://junglewise.ai/threats/cve-2026-13074-mongodb-server-denial-of-service-via-hello-command-exhaust-mode"},{"cve":"CVE-2026-13073","cvss":4.3,"slug":"cve-2026-13073-mongodb-server-denial-of-service-via-crafted-aggregation-command","title":"MongoDB Server denial of service via crafted aggregation command","severity":"medium","exploited":false,"published_at":"2026-07-22T20:16:45.9+00:00","url":"https://junglewise.ai/threats/cve-2026-13073-mongodb-server-denial-of-service-via-crafted-aggregation-command"},{"cve":"CVE-2026-13072","cvss":8.1,"slug":"cve-2026-13072-mongodb-server-heap-overflow-in-aggregation-pipeline-processing","title":"MongoDB Server heap overflow in aggregation pipeline processing","severity":"high","exploited":false,"published_at":"2026-07-22T20:16:45.74+00:00","url":"https://junglewise.ai/threats/cve-2026-13072-mongodb-server-heap-overflow-in-aggregation-pipeline-processing"},{"cve":"CVE-2026-13071","cvss":6.5,"slug":"cve-2026-13071-mongodb-server-use-after-free-in-function-aggregation-operator","title":"MongoDB Server use-after-free in $function aggregation operator","severity":"medium","exploited":false,"published_at":"2026-07-22T20:16:45.58+00:00","url":"https://junglewise.ai/threats/cve-2026-13071-mongodb-server-use-after-free-in-function-aggregation-operator"},{"cve":"CVE-2026-13070","cvss":5.3,"slug":"cve-2026-13070-mongodb-server-denial-of-service-via-malformed-ocsp-response","title":"MongoDB Server denial of service via malformed OCSP response","severity":"medium","exploited":false,"published_at":"2026-07-22T20:16:45.42+00:00","url":"https://junglewise.ai/threats/cve-2026-13070-mongodb-server-denial-of-service-via-malformed-ocsp-response"},{"cve":"CVE-2026-13069","cvss":6.5,"slug":"cve-2026-13069-mongodb-server-denial-of-service-in-queryable-encryption","title":"MongoDB Server denial of service in Queryable Encryption","severity":"medium","exploited":false,"published_at":"2026-07-22T20:16:45.27+00:00","url":"https://junglewise.ai/threats/cve-2026-13069-mongodb-server-denial-of-service-in-queryable-encryption"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":25},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"MongoDB C Driver","slug":"c-driver","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/c-driver"},{"name":"MongoDB","slug":"mongodb","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/mongodb"},{"name":"MongoDB Connector for BI","slug":"connector-for-bi","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/connector-for-bi"},{"name":"MongoDB Bi Connector Odbc Driver","slug":"bi-connector-odbc-driver","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/bi-connector-odbc-driver"},{"name":"MongoDB Mongo-Express","slug":"mongo-express","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/mongo-express"},{"name":"MongoDB Compass","slug":"compass","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/compass"},{"name":"MongoDB Entity Framework Core Provider","slug":"entity-framework-core-provider","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/entity-framework-core-provider"},{"name":"MongoDB Go Driver","slug":"go-driver","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/go-driver"},{"name":"MongoDB Java Driver","slug":"java-driver","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/java-driver"},{"name":"MongoDB Libmongocrypt","slug":"libmongocrypt","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/libmongocrypt"},{"name":"MongoDB Mongosql Transition Readiness Tool","slug":"mongosql-transition-readiness-tool","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/mongosql-transition-readiness-tool"},{"name":"MongoDB PHP Driver","slug":"php-driver","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/php-driver"}],"technology":{"hub":true,"name":"MongoDB Server","slug":"mongodb-server","vendor":{"name":"MongoDB","slug":"mongodb","url":"https://junglewise.ai/threats/vendors/mongodb"},"aliases":[],"category":"database","homepage":"https://www.mongodb.com/","repo_url":"https://github.com/mongodb/mongo","description":"A document-oriented NoSQL database program that uses JSON-like documents with optional schemas.","url":"https://junglewise.ai/threats/technologies/mongodb-server"},"most_severe":[{"cve":"CVE-2025-14847","cvss":8.7,"epss":0.6894,"slug":"cve-2025-14847-mongodb-server-uninitialized-heap-memory-disclosure-in-zlib","title":"MongoDB Server uninitialized heap memory disclosure in Zlib headers","severity":"critical","exploited":true,"published_at":"2025-12-29T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-14847-mongodb-server-uninitialized-heap-memory-disclosure-in-zlib"},{"cve":"CVE-2026-18691","cvss":8.8,"epss":0.0036,"slug":"cve-2026-18691-mongodb-server-sasl-mechanism-downgrade-in-intra-cluster","title":"MongoDB Server SASL mechanism downgrade in intra-cluster authentication","severity":"high","exploited":false,"published_at":"2026-08-11T19:17:22.903+00:00","url":"https://junglewise.ai/threats/cve-2026-18691-mongodb-server-sasl-mechanism-downgrade-in-intra-cluster"},{"cve":"CVE-2026-8053","cvss":8.8,"epss":0.0006,"slug":"cve-2026-8053-mongodb-server-out-of-bounds-write-in-time-series-collections","title":"MongoDB Server out-of-bounds write in time-series collections","severity":"high","exploited":false,"published_at":"2026-05-13T04:17:41.287+00:00","url":"https://junglewise.ai/threats/cve-2026-8053-mongodb-server-out-of-bounds-write-in-time-series-collections"},{"cve":"CVE-2026-11933","cvss":8.8,"slug":"cve-2026-11933-mongodb-server-use-after-free-in-server-side-javascript-engine","title":"MongoDB Server use-after-free in server-side JavaScript engine","severity":"high","exploited":false,"published_at":"2026-06-12T02:16:38.527+00:00","url":"https://junglewise.ai/threats/cve-2026-11933-mongodb-server-use-after-free-in-server-side-javascript-engine"},{"cve":"CVE-2026-82053","cvss":8.1,"epss":0.0041,"slug":"cve-2026-82053-mongodb-ldap-connection-pooling-privilege-escalation","title":"MongoDB LDAP connection pooling privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-08T17:18:33.143+00:00","url":"https://junglewise.ai/threats/cve-2026-82053-mongodb-ldap-connection-pooling-privilege-escalation"},{"cve":"CVE-2026-13072","cvss":8.1,"slug":"cve-2026-13072-mongodb-server-heap-overflow-in-aggregation-pipeline-processing","title":"MongoDB Server heap overflow in aggregation pipeline processing","severity":"high","exploited":false,"published_at":"2026-07-22T20:16:45.74+00:00","url":"https://junglewise.ai/threats/cve-2026-13072-mongodb-server-heap-overflow-in-aggregation-pipeline-processing"},{"cve":"CVE-2026-13059","cvss":8.1,"slug":"cve-2026-13059-mongodb-server-authorization-bypass-in-query-level-access","title":"MongoDB Server authorization bypass in query-level access controls","severity":"high","exploited":false,"published_at":"2026-07-22T20:16:43.793+00:00","url":"https://junglewise.ai/threats/cve-2026-13059-mongodb-server-authorization-bypass-in-query-level-access"},{"cve":"CVE-2026-9753","cvss":8.1,"slug":"cve-2026-9753-mongodb-server-out-of-bounds-read-in-internalapplyoplogupdate","title":"MongoDB Server out-of-bounds read in $_internalApplyOplogUpdate","severity":"high","exploited":false,"published_at":"2026-06-09T23:17:04.897+00:00","url":"https://junglewise.ai/threats/cve-2026-9753-mongodb-server-out-of-bounds-read-in-internalapplyoplogupdate"},{"cve":"CVE-2026-13078","cvss":7.7,"slug":"cve-2026-13078-mongodb-server-arbitrary-file-read-in-mozjs-scripting-engine","title":"MongoDB Server arbitrary file read in MozJS scripting engine","severity":"high","exploited":false,"published_at":"2026-07-22T20:16:46.65+00:00","url":"https://junglewise.ai/threats/cve-2026-13078-mongodb-server-arbitrary-file-read-in-mozjs-scripting-engine"},{"cve":"CVE-2026-82064","cvss":7.5,"epss":0.0052,"slug":"cve-2026-82064-mongodb-server-denial-of-service-in-read-concern-processing","title":"MongoDB Server denial of service in read concern processing","severity":"high","exploited":false,"published_at":"2026-09-08T17:18:35.233+00:00","url":"https://junglewise.ai/threats/cve-2026-82064-mongodb-server-denial-of-service-in-read-concern-processing"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}