CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-25613

mediumcovered by 1 sourcefirst seen 2026-08-13
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in MongoDB to execute arbitrary Ruby code, bypass authorization, cause a denial-of-service condition, disclose confidential information, or cause unspecified impacts.

CSIRTS triage

What
Multiple vulnerabilities in MongoDB Server, Go Driver, and Ruby Driver allow attackers to execute arbitrary Ruby code, bypass authorization, cause denial-of-service, or disclose confidential information.
Who is affected
Remote and authenticated attackers can exploit these vulnerabilities in affected MongoDB deployments and driver versions.
Urgency
Medium urgency; remediation is needed but exploitation has not been reported in the wild.
Action
Update MongoDB Server and associated drivers to patched versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-25613

Get an email if CVE-2026-25613 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-25613

CVE.org record

Embed the live status

CVE-2026-25613 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-25613 status](https://www.csirts.com/badge/CVE-2026-25613)](https://www.csirts.com/cve/CVE-2026-25613)