news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans MongoDB (24 juillet 2026)

High
Summary

Multiple vulnerabilities have been discovered in MongoDB, allowing an attacker to cause a denial of service and potentially exploit a security policy bypass. These vulnerabilities affect various versions of MongoDB Compass and Core Server. Users are advised to refer to the MongoDB security bulletins for available patches and updates. Several CVEs have been assigned, including CVE-2026-13055 through CVE-2026-13078.

Multiple vulnerabilities exist within MongoDB, impacting various versions of the database software. These vulnerabilities can lead to a denial of service and potentially allow an attacker to circumvent security policies. Specifically, vulnerabilities have been identified in MongoDB Compass versions prior to 1.49.7 and Core Server versions 7.0.x (prior to 7.0.39), 8.0.x (prior to 8.0.28), 8.2.x (prior to 8.2.12), 8.3.x (prior to 8.3.7). The vulnerabilities are detailed in MongoDB security bulletins, which can be found at the links provided in the documentation section. These vulnerabilities are associated with CVE identifiers including CVE-2026-13055 through CVE-2026-13078. Users are strongly encouraged to update to the latest stable version of MongoDB to mitigate these risks. The MongoDB security bulletins provide specific instructions for patching and upgrading.

Read the full article at CERT-FR