MongoDB Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple vulnerabilities in MongoDB of unknown type and impact.
- Who is affected
- MongoDB installations with affected versions.
- Urgency
- Severity and exploitability unknown; monitor vendor advisories for details.
- Action
- Check MongoDB security advisories for affected versions and apply patches when released.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MongoDB
Get an email when a new MongoDB advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/mongodb-multiple-vulnerabilities_20260813
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-186870.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186880.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186900.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186910.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186920.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186930.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186940.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186950.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186960.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186970.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] MongoDB: Multiple Vulnerabilitiescert-bund
- mediumCVE-2026-18710: A MongoDB driver component could write sensitive configuration information, including a creden…nvd
- highCVE-2026-18712: An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authen…nvd
- highCVE-2026-18711: An issue in MongoDB Server's query execution engine could allow an authenticated user with rea…nvd
- mediumCVE-2026-18709: An issue in MongoDB Server could allow an authenticated user with direct network access to a s…nvd
- mediumCVE-2026-18708: An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user wit…nvd
- mediumCVE-2026-18707: An issue in MongoDB Server could allow an authenticated user, including one with no assigned p…nvd
- mediumCVE-2026-18706: An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user …nvd
- mediumCVE-2026-18705: An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user wit…nvd
- mediumCVE-2026-18704: An issue in MongoDB Server's aggregation framework could allow an authenticated user with only…nvd
- mediumCVE-2026-18703: An issue in MongoDB Server could allow a party with a valid client certificate and a correspon…nvd
- mediumCVE-2026-18702: An issue in MongoDB Server could allow an authenticated user with limited, database-scoped pri…nvd
More from HKCERT Security Bulletins
- unknownMicrosoft Edge Multiple Vulnerabilities2026-08-17
- unknownVMWare Products Multiple Vulnerabilities2026-08-14
- unknownPalo Alto Products Multiple Vulnerabilities2026-08-14
- unknownIBM WebSphere Products Multiple Vulnerabilities2026-08-13
- unknownFortinet Products Multiple Vulnerabilities2026-08-13