news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans MongoDB (07 septembre 2026)

MediumCVSS 6.5
Summary

Multiple vulnerabilities have been discovered in MongoDB, including issues impacting data integrity, confidentiality, and allowing for cross-site request forgery (CSRF). These vulnerabilities affect various MongoDB drivers and components, requiring immediate patching to mitigate potential risks. Several CVEs have been assigned to these flaws.

A security bulletin from CERT-FR details multiple vulnerabilities within MongoDB. These vulnerabilities span several components, including the C Driver, C++ Driver, MongoDB for VS Code, and MongoDB Cryptographic Library (libmongocrypt). Specifically, versions of C Driver (2.x and 1.30.9) and C++ Driver (4.5.2) are affected, alongside libmongocrypt versions prior to 1.20.4. MongoDB for VS Code versions before 1.17.1, PHP Driver versions (2.1.x and 2.2.x), and PHP Driver versions (1.21.8) are also vulnerable. The bulletin highlights the potential for attackers to compromise data integrity and confidentiality, as well as exploit CSRF vulnerabilities. Several CVEs have been assigned to these issues, including CVE-2026-84962 through CVE-2026-84971. Affected products include MongoDB C Driver, C++ Driver, MongoDB for VS Code, PHP Driver, and MongoDB Cryptographic Library. Users are advised to consult the linked security bulletins for detailed information and to apply the necessary patches immediately.

Read the full article at CERT-FR