CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[UPDATE] [hoch] MongoDB: Mehrere Schwachstellen

highCVE-2026-82052CVE-2026-87803CVE-2026-88022CVE-2026-88023CVE-2026-88024CVE-2026-88025
Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Abfrage- und Zugriffsbeschränkungen zu umgehen, nicht vorgesehene Datensätze oder Dateien auszulesen, zu verändern oder zu löschen sowie unter bestimmten Voraussetzungen MongoDB-Server oder Anwendungen zum Absturz zu bringen und dadurch einen Denial-of-Service zu verursachen.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-09-15
Exploitation
Not in CISA KEV at last sync

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3320

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-82052coverage & exploitation statusNVD · CVE.org
CVE-2026-87803coverage & exploitation statusNVD · CVE.org
CVE-2026-88022coverage & exploitation statusNVD · CVE.org
CVE-2026-88023coverage & exploitation statusNVD · CVE.org
CVE-2026-88024coverage & exploitation statusNVD · CVE.org
CVE-2026-88025coverage & exploitation statusNVD · CVE.org
CVE-2026-88026coverage & exploitation statusNVD · CVE.org
CVE-2026-88027coverage & exploitation statusNVD · CVE.org
CVE-2026-88028coverage & exploitation statusNVD · CVE.org
CVE-2026-88029coverage & exploitation statusNVD · CVE.org
CVE-2026-88030coverage & exploitation statusNVD · CVE.org
CVE-2026-88031coverage & exploitation statusNVD · CVE.org
CVE-2026-88032coverage & exploitation statusNVD · CVE.org
CVE-2026-88033coverage & exploitation statusNVD · CVE.org
CVE-2026-88034coverage & exploitation statusNVD · CVE.org
CVE-2026-88035coverage & exploitation statusNVD · CVE.org
CVE-2026-88036coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CERT-Bund (BSI) Security Advisories