[UPDATE] [hoch] MongoDB: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um beliebigen Programmcode auszuführen.
CSIRTS triage
- What
- Multiple critical vulnerabilities enable authentication bypass, denial of service, information disclosure, file manipulation, and remote code execution.
- Who is affected
- All MongoDB deployments are at risk from multiple attack vectors including remote code execution.
- Urgency
- Critical; multiple severe classes including unauthenticated RCE require immediate remediation.
- Action
- Update MongoDB to the latest patched version immediately and review network access controls.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MongoDB
Get an email when a new MongoDB advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2794
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-186870.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186880.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186900.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186910.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186920.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186930.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186940.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186950.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186960.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186970.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMongoDB Multiple Vulnerabilitieshkcert
- mediumCVE-2026-18710: A MongoDB driver component could write sensitive configuration information, including a creden…nvd
- highCVE-2026-18712: An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authen…nvd
- highCVE-2026-18711: An issue in MongoDB Server's query execution engine could allow an authenticated user with rea…nvd
- mediumCVE-2026-18709: An issue in MongoDB Server could allow an authenticated user with direct network access to a s…nvd
- mediumCVE-2026-18708: An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user wit…nvd
- mediumCVE-2026-18707: An issue in MongoDB Server could allow an authenticated user, including one with no assigned p…nvd
- mediumCVE-2026-18706: An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user …nvd
- mediumCVE-2026-18705: An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user wit…nvd
- mediumCVE-2026-18704: An issue in MongoDB Server's aggregation framework could allow an authenticated user with only…nvd
- mediumCVE-2026-18703: An issue in MongoDB Server could allow a party with a valid client certificate and a correspon…nvd
- mediumCVE-2026-18702: An issue in MongoDB Server could allow an authenticated user with limited, database-scoped pri…nvd
Recent advisories for MongoDB
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEU] [hoch] MongoDB: Mehrere Schwachstellencert-bund · 2026-09-11
- highCVE-2026-88036: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd · 2026-09-10
- mediumCVE-2026-88035: A size check in the client-side authentication path of the MongoDB C Driver can wrap around, s…nvd · 2026-09-10
- highCVE-2026-88034: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd · 2026-09-10
- highCVE-2026-88033: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd · 2026-09-10
- mediumCVE-2026-88032: A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver c…nvd · 2026-09-10
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11