news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans MongoDB (14 septembre 2026)

HighCVSS 8.3
Summary

Multiple vulnerabilities have been discovered in MongoDB, including those that could lead to data integrity compromise, data confidentiality breaches, and denial of service attacks. These vulnerabilities affect various MongoDB drivers and server components, spanning versions from C Driver 1.30.10 to Server 8.3.11. The vulnerabilities are linked to CVE-2026-88022 through CVE-2026-89099, and require immediate patching to mitigate potential risks.

MongoDB has announced multiple security vulnerabilities affecting its drivers and server components. These vulnerabilities could allow an attacker to compromise data integrity, steal sensitive data, or cause a denial of service. Specifically, the vulnerabilities include issues in the C Driver, C# Driver, C++ Driver, Go Driver, Java Driver, PHP Driver, PHP Laravel MongoDB Integration, Python Driver, Ruby Driver, Rust Driver, and Server components. The vulnerabilities are linked to a series of CVEs, including CVE-2026-88022 through CVE-2026-89099. Affected MongoDB versions include C Driver versions prior to 1.30.10, C Driver versions prior to 2.5.3, C# Driver versions prior to 3.11.2, C++ Driver versions prior to 4.5.3, Go Driver versions prior to 1.17.10 and 2.9.1, Java Driver versions prior to 5.11.1, PHP Driver versions prior to 1.21.5 and 2.4.2, PHP Laravel MongoDB Integration version prior to 5.11.0, Python Driver versions prior to 4.18.1, Ruby Driver versions prior to 2.26.0, Rust Driver versions prior to 3.9.1, and MongoDB Server versions prior to 8.3.11. CERT-FR has published detailed security bulletins for each of these vulnerabilities. Users are strongly advised to apply the recommended patches immediately to address these security concerns.

Read the full article at CERT-FR