MongoDB Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple vulnerabilities have been identified in MongoDB.
- Who is affected
- Deployments of MongoDB are affected.
- Urgency
- Remediation is not urgent as there is no known exploitation.
- Action
- Monitor for updates and apply patches when available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MongoDB
Get an email when a new MongoDB advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/mongodb-multiple-vulnerabilities_20260724
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-97370.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-130550.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-130560.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-130570.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-130580.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-130590.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all scored CVEs.
- Low exploitation riskCVE-2026-130600.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-130610.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-130620.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
- Low exploitation riskCVE-2026-130630.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in MongoDB (July 24, 2026)cert-fr-avis
- high[NEW] [high] MongoDB: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-9737: During query planning when reading the sort pattern in raw BSONObj form, in some places we don’…nvd
- highCVE-2026-14881: When importing connections in Compass it is possible to override some connection options that …nvd
- highCVE-2026-13078: A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine …nvd
- highCVE-2026-13077: A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger …nvd
- mediumCVE-2026-13076: An authenticated user can cause a {{mongod}} process to be terminated by the operating system …nvd
- mediumCVE-2026-13075: An authenticated user can cause the mongod process to be terminated by the operating system un…nvd
- mediumCVE-2026-13074: An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by se…nvd
- mediumCVE-2026-13073: An authenticated user with read-only privileges can cause the mongod process to terminate abno…nvd
- highCVE-2026-13072: When compute mode is enabled on a standalone mongod instance, insufficient validation of exter…nvd
- mediumCVE-2026-13071: An authenticated user with read access can cause the mongod process to be terminated through c…nvd
More from HKCERT Security Bulletins
- unknownGoogle Chrome Multiple Vulnerabilities2026-07-30
- unknownCisco Secure Firewall Management Center Software Information Disclosure Vulnerability2026-07-30
- unknownIBM WebSphere Products Multiple Vulnerabilities2026-07-30
- unknownNode.js Multiple Vulnerabilities2026-07-30
- unknownXen Multiple Vulnerabilities2026-07-30