Multiples vulnérabilités dans MongoDB Server (10 septembre 2026)
Multiple vulnerabilities have been discovered in MongoDB Server, impacting various versions. These vulnerabilities allow for data integrity compromise, data confidentiality breaches, and remote code execution, alongside denial-of-service attacks and cross-site request forgery. Affected MongoDB versions include several releases across 7.x, 8.0.x, 8.2.x, 8.3.x, and 9.x. Users are advised to refer to the MongoDB security bulletins for specific patching instructions.
Multiple vulnerabilities exist within MongoDB Server, posing significant security risks. These vulnerabilities can lead to data integrity compromise, data confidentiality breaches, and the ability for attackers to execute code remotely. Specifically, the vulnerabilities include remote code execution, denial-of-service attacks, and cross-site request forgery (CSRF). Affected MongoDB versions include: 7.x (prior to 7.0.41), 8.0.x (prior to 8.0.30), 8.2.x (prior to 8.2.13), 8.3.x (prior to 8.3.9), and 9.x (prior to 9.0.0-rc2). The vulnerabilities have been identified through security bulletins released by MongoDB. Several CVE identifiers have been assigned to these vulnerabilities, including CVE-2026-82052 through CVE-2026-82076. Refer to the official MongoDB security bulletins for detailed information on how to remediate these issues and apply the necessary patches. These bulletins can be found at the links provided in the documentation section.