[UPDATE] [medium] MongoDB Server, Go Driver, Ruby Driver: Multiple vulnerabilities
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in MongoDB to execute arbitrary Ruby code, bypass authorization, cause a denial-of-service condition, disclose confidential information, or cause unspecified impacts.
CSIRTS triage
- What
- Multiple vulnerabilities in MongoDB Server, Go Driver, and Ruby Driver allow attackers to execute arbitrary Ruby code, bypass authorization, cause denial-of-service, or disclose confidential information.
- Who is affected
- Remote and authenticated attackers can exploit these vulnerabilities in affected MongoDB deployments and driver versions.
- Urgency
- Medium urgency; remediation is needed but exploitation has not been reported in the wild.
- Action
- Update MongoDB Server and associated drivers to patched versions.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0386
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-23030.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-23020.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-18490.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-256090.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-18470.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-256130.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-18500.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-18480.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-256120.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-256110.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-2303 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-2302 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-1849 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25609 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-1847 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25613 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-1850 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-1848 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25612 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25611 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25610 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for MongoDB Server
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-73618: Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query ex…nvd · 2026-08-13
- highCVE-2026-18712: An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authen…nvd · 2026-08-11
- highCVE-2026-18711: An issue in MongoDB Server's query execution engine could allow an authenticated user with rea…nvd · 2026-08-11
- mediumCVE-2026-18709: An issue in MongoDB Server could allow an authenticated user with direct network access to a s…nvd · 2026-08-11
- mediumCVE-2026-18708: An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user wit…nvd · 2026-08-11
- mediumCVE-2026-18707: An issue in MongoDB Server could allow an authenticated user, including one with no assigned p…nvd · 2026-08-11
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] GStreamer: Multiple Vulnerabilities2026-08-17
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-08-17
- medium[NEW] [medium] Apache Struts: Multiple vulnerabilities2026-08-17
- high[NEW] [high] PostgreSQL: Multiple vulnerabilities2026-08-17
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilities2026-08-17