Multiples vulnérabilités dans MongoDB (14 septembre 2026)
De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1169/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-880260.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-880280.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-880250.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-880220.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-880310.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-880320.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-880270.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-890990.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-880360.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-880240.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-88026 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88028 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88025 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88022 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88031 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88032 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88027 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-89099 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88036 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88024 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88033 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88034 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88023 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88029 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88030 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-88035 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] MongoDB: Mehrere Schwachstellencert-bund
- highCVE-2026-89099: A race condition in the document value layer of MongoDB Server can allow concurrent server thr…nvd
- highCVE-2026-88036: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd
- mediumCVE-2026-88035: A size check in the client-side authentication path of the MongoDB C Driver can wrap around, s…nvd
- highCVE-2026-88034: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd
- highCVE-2026-88033: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd
- mediumCVE-2026-88032: A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver c…nvd
- highCVE-2026-88031: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd
- highCVE-2026-88030: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd
- highCVE-2026-88029: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd
- mediumCVE-2026-88028: Improper neutralization of special elements in data query logic in the polymorphic relation ha…nvd
- highCVE-2026-88027: Improper neutralization of special elements in data query logic in the embedded-document relat…nvd
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Microsoft Edge (15 septembre 2026)2026-09-15
- unknownVulnérabilité dans Microsoft Windows (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Cisco (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Apple (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans Squid (14 septembre 2026)2026-09-14