CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-25610

mediumcovered by 1 sourcefirst seen 2026-08-13
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in MongoDB to execute arbitrary Ruby code, bypass authorization, cause a denial-of-service condition, disclose confidential information, or cause unspecified impacts.

CSIRTS triage

What
Multiple vulnerabilities in MongoDB Server, Go Driver, and Ruby Driver allow attackers to execute arbitrary Ruby code, bypass authorization, cause denial-of-service, or disclose confidential information.
Who is affected
Remote and authenticated attackers can exploit these vulnerabilities in affected MongoDB deployments and driver versions.
Urgency
Medium urgency; remediation is needed but exploitation has not been reported in the wild.
Action
Update MongoDB Server and associated drivers to patched versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-25610

Get an email if CVE-2026-25610 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-25610

CVE.org record

Embed the live status

CVE-2026-25610 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-25610 status](https://www.csirts.com/badge/CVE-2026-25610)](https://www.csirts.com/cve/CVE-2026-25610)