[NEU] [hoch] MongoDB Server: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in MongoDB Server ausnutzen, um erweiterte Berechtigungen, einschließlich Administratorrechte, zu erlangen und beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3236
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-820520.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820530.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820540.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820550.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820560.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820570.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820580.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820590.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820600.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820610.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMongoDB Multiple Vulnerabilitieshkcert
- mediumCVE-2026-82076: An integer overflow in the query planning component of MongoDB Server can allow an authenticat…nvd
- mediumCVE-2026-82074: MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework.…nvd
- mediumCVE-2026-82073: A security issue in the MongoDB Server aggregation framework allows an authenticated user with…nvd
- highCVE-2026-82071: Insufficient validation of storage engine configuration options in MongoDB Server allows an au…nvd
- mediumCVE-2026-82070: A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated us…nvd
- lowCVE-2026-82069: A security issue in MongoDB Server's query statistics serialization on the router allows users…nvd
- mediumCVE-2026-82068: A security issue in MongoDB Server allows an authenticated user with write privileges to trigg…nvd
- highCVE-2026-82067: Improper handling of case sensitivity in the configuration validation component of MongoDB Ser…nvd
- mediumCVE-2026-82066: A heap out-of-bounds read security issue exists in the query planning component of MongoDB Ser…nvd
- mediumCVE-2026-82065: A security issue in the MongoDB Server's storage engine integration layer allows an authentica…nvd
- highCVE-2026-82064: A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of…nvd
Recent advisories for MongoDB Server
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-82076: An integer overflow in the query planning component of MongoDB Server can allow an authenticat…nvd · 2026-09-08
- mediumCVE-2026-82074: MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework.…nvd · 2026-09-08
- mediumCVE-2026-82073: A security issue in the MongoDB Server aggregation framework allows an authenticated user with…nvd · 2026-09-08
- highCVE-2026-82071: Insufficient validation of storage engine configuration options in MongoDB Server allows an au…nvd · 2026-09-08
- mediumCVE-2026-82070: A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated us…nvd · 2026-09-08
- lowCVE-2026-82069: A security issue in MongoDB Server's query statistics serialization on the router allows users…nvd · 2026-09-08
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10