Multiples vulnérabilités dans MongoDB Server (10 septembre 2026)
De multiples vulnérabilités ont été découvertes dans MongoDB Server. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1157/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-820670.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820580.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820550.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820700.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820620.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820540.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820610.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820660.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820690.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-820740.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMongoDB Multiple Vulnerabilitieshkcert
- high[NEU] [hoch] MongoDB Server: Mehrere Schwachstellencert-bund
- mediumCVE-2026-82076: An integer overflow in the query planning component of MongoDB Server can allow an authenticat…nvd
- highCVE-2026-82075: An uncontrolled resource consumption weakness exists in the request-handling path of the Mongo…nvd
- mediumCVE-2026-82074: MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework.…nvd
- mediumCVE-2026-82073: A security issue in the MongoDB Server aggregation framework allows an authenticated user with…nvd
- highCVE-2026-82071: Insufficient validation of storage engine configuration options in MongoDB Server allows an au…nvd
- mediumCVE-2026-82070: A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated us…nvd
- lowCVE-2026-82069: A security issue in MongoDB Server's query statistics serialization on the router allows users…nvd
- mediumCVE-2026-82068: A security issue in MongoDB Server allows an authenticated user with write privileges to trigg…nvd
- highCVE-2026-82067: Improper handling of case sensitivity in the configuration validation component of MongoDB Ser…nvd
- mediumCVE-2026-82066: A heap out-of-bounds read security issue exists in the query planning component of MongoDB Ser…nvd
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans les produits Palo Alto Networks (10 septembre 2026)2026-09-10
- unknownVulnérabilité dans Apereo CAS (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans HPE Aruba Networking ClearPass Policy Manager (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans les produits Check Point (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans Moodle (10 septembre 2026)2026-09-10