Vulnerabilidades en MONGODB
50 resultadosAnálisis Vexday
MongoDB apresenta um perfil de risco mínimo com apenas 1 CVE crítica registrada na base, sem evidência atual de exploração em ataques documentados. A vulnerabilidade não é recente e está associada à fraqueza CWE-1104 (Use of Unmaintained Third Party Components), indicando risco potencial relacionado a dependências obsoletas em vez de falhas diretas do produto.
CVE-2026-14881HIGHCompass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flowEPSS 0.2%CVE-2026-13068LOWMongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege MisuseEPSS 0.1%CVE-2025-12100HIGHMongoDB BI Connector ODBC driver installation via MSI may leave ACLs unset on custom installation directoriesEPSS 0.1%CVE-2025-11575HIGHMongoDB Atlas SQL ODBC driver installation via MSI may leave ACLs unset on custom installation directoriesEPSS 0.1%CVE-2026-9735MEDIUMKeyfile contents are in MongoDB Server logsEPSS 0.1%CVE-2026-13062HIGHMongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded ClustersEPSS 0.1%CVE-2026-9751MEDIUMSensitive data could be written to mongod.logEPSS 0.1%CVE-2026-9741HIGHClient side encryption fails to encrypt values in a $vectorSearchEPSS 0.1%CVE-2026-13070MEDIUMImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process TerminationEPSS 0.1%CVE-2026-13067HIGHtlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain SocketEPSS 0.1%