[NEW] [high] MongoDB: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in MongoDB to execute arbitrary code, bypass security measures, manipulate data, disclose sensitive information or trigger a Denial-of-Service condition.
CSIRTS triage
- What
- Multiple vulnerabilities in MongoDB allow attackers to execute arbitrary code, bypass security measures, manipulate data, disclose sensitive information, and trigger denial of service.
- Who is affected
- MongoDB deployments of unspecified versions are affected.
- Urgency
- High urgency; code execution and information disclosure risks warrant immediate remediation.
- Action
- Update MongoDB to a patched version addressing CVE-2026-18888, CVE-2026-19001, CVE-2026-19002, CVE-2026-19003, CVE-2026-19004, CVE-2026-19502, and CVE-2026-19503.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MongoDB
Get an email when a new MongoDB advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2818
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-188880.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-190010.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-190020.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-190030.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-190040.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195020.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195030.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18888 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19001 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19002 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19003 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19004 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19502 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19503 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-19003: A data source definition containing an over-length file path setting may cause the MongoDB BI …nvd
- mediumCVE-2026-19503: MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the aut…nvd
- mediumCVE-2026-19502: MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when …nvd
- highCVE-2026-19004: An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue…nvd
- highCVE-2026-19002: A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Conn…nvd
- criticalCVE-2026-19001: The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when …nvd
- mediumCVE-2026-18888: The MongoDB BI Connector ODBC Driver converts floating point column values into text without c…nvd
Recent advisories for MongoDB
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-72857: Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, a…nvd · 2026-08-13
- mediumCVE-2026-73562: Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Pr…nvd · 2026-08-13
- highCVE-2026-73618: Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query ex…nvd · 2026-08-13
- highCVE-2026-73617: Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource inte…nvd · 2026-08-13
- medium[UPDATE] [medium] MongoDB Server, Go Driver, Ruby Driver: Multiple vulnerabilitiescert-bund · 2026-08-13
- unknownMongoDB Multiple Vulnerabilitieshkcert · 2026-08-13
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] GStreamer: Multiple Vulnerabilities2026-08-17
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-08-17
- medium[NEW] [medium] Apache Struts: Multiple vulnerabilities2026-08-17
- high[NEW] [high] PostgreSQL: Multiple vulnerabilities2026-08-17
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilities2026-08-17