Known Vulnerabilities for MongoDB Server by MongoDB
Listed below are 10 of the newest known vulnerabilities associated with "MongoDB Server" by "MongoDB".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-84970 json | A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who con... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-81528 json | A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths ap... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-81526 json | The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in ... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-81490 json | A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling rout... | Not Provided | 2026-08-28 | 2026-08-31 |
| CVE-2026-77586 json | In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted ident... | Not Provided | 2026-08-28 | 2026-08-31 |
| CVE-2026-77184 json | In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment te... | Not Provided | 2026-08-28 | 2026-08-31 |
| CVE-2026-77070 json | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggr... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-73618 json | Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-sup... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-73409 json | Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-con... | Not Provided | 2026-08-12 | 2026-08-14 |
| CVE-2026-72881 json | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders... | Not Provided | 2026-08-10 | 2026-08-10 |