CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

MongoDB security advisory (AV26-744)

unknown
Serial number: AV26-744 Date: July 24, 2026 On July 22, 2026, MongoDB published security advisories to address vulnerabilities in the following products: MongoDB Compass – versions prior to 1.49.7 MongoDB Server – versions prior to 7.0.39 MongoDB Server – versions prior to 8.0.28 MongoDB Server – versions prior to 8.2.12 MongoDB Server – versions prior to 8.3.7 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Security Related: Common Vulnerabilities and Exposures (CVEs) MongoDB Alerts

CSIRTS triage

vendor: MongoDBaffected: prior to 1.49.7, prior to 7.0.39, prior to 8.0.28, prior to 8.2.12, prior to 8.3.7
What
The advisory addresses vulnerabilities in multiple MongoDB products.
Who is affected
Users and administrators of MongoDB Compass and MongoDB Server versions listed are affected.
Urgency
Remediation is encouraged due to the presence of vulnerabilities, though severity is unknown.
Action
Users should review the advisory and apply the necessary updates.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-07-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/mongodb-security-advisory-av26-744

More from Canadian Centre for Cyber Security