[UPDATE] [hoch] MongoDB Clients: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in verschiedenen MongoDB Clients ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder Denial-of-Service-Zustände herbeizuführen.
CSIRTS triage
- What
- Multiple vulnerabilities across MongoDB Clients enable security bypass, information disclosure, data manipulation, and denial of service.
- Who is affected
- Various MongoDB client implementations and versions are affected.
- Urgency
- High severity; multiple bypass and disclosure vectors in database clients warrant rapid remediation.
- Action
- Update all MongoDB Client libraries and implementations to the latest patched versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MongoDB Clients
Get an email when a new MongoDB Clients advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3066
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-751590.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-755730.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-815210.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-815220.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-815230.07% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-815240.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-815250.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-815260.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-815270.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-815280.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-75159 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75573 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81521 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81522 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81523 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81524 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81525 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81526 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81527 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81528 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81529 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81530 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highGHSA-65fr-j4p9-vc33: mongodb: Reject "." and NUL bytes in database and collection namesghsa
- mediumCVE-2026-81530: A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes…nvd
- highCVE-2026-81529: Improper neutralization of delimiters in connection-URL construction allows connection-option …nvd
- mediumCVE-2026-81528: A MongoDB C# driver document-replacement code path omits the element-name/shape validation tha…nvd
- mediumCVE-2026-81527: A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation laye…nvd
- mediumCVE-2026-81526: The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target ide…nvd
- highCVE-2026-81525: The MongoDB client library for PHP does not sufficiently sanitize special elements in applicat…nvd
- mediumCVE-2026-81524: A weakness in the MongoDB C Driver allows special elements in caller-supplied database and col…nvd
- mediumCVE-2026-81523: A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup…nvd
- highCVE-2026-81522: A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allow…nvd
- mediumCVE-2026-81521: The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied databas…nvd
- mediumCVE-2026-75573: In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error …nvd
Recent advisories for MongoDB Clients
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-88035: A size check in the client-side authentication path of the MongoDB C Driver can wrap around, s…nvd · 2026-09-10
- mediumCVE-2026-88032: A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver c…nvd · 2026-09-10
- highCVE-2026-82075: An uncontrolled resource consumption weakness exists in the request-handling path of the Mongo…nvd · 2026-09-08
- mediumCVE-2026-84964: A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C D…nvd · 2026-09-03
- highCVE-2026-81520: A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI …nvd · 2026-08-28
- mediumCVE-2026-81530: A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes…nvd · 2026-08-27
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11