MongoDB Multiple Vulnerabilities
Details
Original advisory: https://www.hkcert.org/security-bulletin/mongodb-multiple-vulnerabilities_20260910
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-820520.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820530.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820540.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820550.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820560.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820570.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820580.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820590.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820600.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820610.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] MongoDB Server: Mehrere Schwachstellencert-bund
- mediumCVE-2026-82076: An integer overflow in the query planning component of MongoDB Server can allow an authenticat…nvd
- highCVE-2026-82075: An uncontrolled resource consumption weakness exists in the request-handling path of the Mongo…nvd
- mediumCVE-2026-82074: MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework.…nvd
- mediumCVE-2026-82073: A security issue in the MongoDB Server aggregation framework allows an authenticated user with…nvd
- highCVE-2026-82071: Insufficient validation of storage engine configuration options in MongoDB Server allows an au…nvd
- mediumCVE-2026-82070: A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated us…nvd
- lowCVE-2026-82069: A security issue in MongoDB Server's query statistics serialization on the router allows users…nvd
- mediumCVE-2026-82068: A security issue in MongoDB Server allows an authenticated user with write privileges to trigg…nvd
- highCVE-2026-82067: Improper handling of case sensitivity in the configuration validation component of MongoDB Ser…nvd
- mediumCVE-2026-82066: A heap out-of-bounds read security issue exists in the query planning component of MongoDB Ser…nvd
- mediumCVE-2026-82065: A security issue in the MongoDB Server's storage engine integration layer allows an authentica…nvd
More from HKCERT Security Bulletins
- unknownPalo Alto Products Multiple Vulnerabilities2026-09-10
- unknownGoogle Chrome Multiple Vulnerabilities2026-09-10
- unknownCitrix Products Multiple Vulnerabilities2026-09-10
- unknownAdobe Monthly Security Update (September 2026)2026-09-09
- unknownMozilla Firefox Denial of Service Vulnerability2026-09-09