Known Vulnerabilities for MongoDB Server by MongoDB

Listed below are 10 of the newest known vulnerabilities associated with "MongoDB Server" by "MongoDB".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-84970 json A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who con... Not Provided 2026-09-03 2026-09-03
CVE-2026-81528 json A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths ap... Not Provided 2026-08-27 2026-08-28
CVE-2026-81526 json The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in ... Not Provided 2026-08-27 2026-08-28
CVE-2026-81490 json A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling rout... Not Provided 2026-08-28 2026-08-31
CVE-2026-77586 json In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted ident... Not Provided 2026-08-28 2026-08-31
CVE-2026-77184 json In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment te... Not Provided 2026-08-28 2026-08-31
CVE-2026-77070 json n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggr... Not Provided 2026-08-20 2026-08-21
CVE-2026-73618 json Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-sup... Not Provided 2026-08-13 2026-08-13
CVE-2026-73409 json Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-con... Not Provided 2026-08-12 2026-08-14
CVE-2026-72881 json Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders... Not Provided 2026-08-10 2026-08-10

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report