Multiple Vulnerabilities in MongoDB Core Server and Compass
Numerous vulnerabilities across MongoDB Core Server and Compass, identified as CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, enable attackers to bypass security policies and induce denial-of-service conditions, necessitating immediate patching.
CERT-FR has issued an advisory regarding multiple vulnerabilities discovered in MongoDB products, specifically affecting MongoDB Core Server and MongoDB Compass. These 26 distinct vulnerabilities, ranging from CVE-2026-13055 to CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, were initially detailed in MongoDB security bulletins on July 22, 2026. While no specific threat actor or active exploitation campaign has been identified, these flaws pose significant risks. Attackers could leverage these vulnerabilities to circumvent security policies, trigger denial-of-service (DoS) conditions, and exploit other unspecified security problems. Organizations using affected versions of MongoDB should prioritize applying the recommended patches to mitigate potential risks to their data and service availability.
Impact
Successful exploitation of these vulnerabilities could lead to significant damage. An attacker could bypass existing security policies, potentially gaining unauthorized access to sensitive data or functionality within the MongoDB environment. The denial-of-service vulnerabilities could allow an attacker to disrupt the availability of MongoDB databases and applications relying on them, leading to operational outages and financial losses. Furthermore, the presence of "unspecified security issues" suggests that other, potentially more severe, impacts may be possible depending on the specific vulnerability and how it is exploited, including data corruption or unauthorized data modification.
Recommendation
- Refer to the MongoDB security bulletins referenced in this brief (e.g., SERVER-123081, SERVER-124355) and apply all necessary patches to update affected MongoDB Core Server and Compass instances to the patched versions.
- Patch CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737 on all affected MongoDB installations immediately.
- Ensure that MongoDB Compass is updated to version 1.49.7 or later.
- Upgrade MongoDB Core Server to versions 7.0.39 or later, 8.0.28 or later, 8.2.12 or later, or 8.3.7 or later, depending on the major version deployed.
Indicators of compromise
52
url
| Type | Value |
|---|---|
| url | https://jira.mongodb.org/browse/SERVER-123081 |
| url | https://jira.mongodb.org/browse/SERVER-124355 |
| url | https://jira.mongodb.org/browse/SERVER-125872 |
| url | https://jira.mongodb.org/browse/SERVER-126247 |
| url | https://jira.mongodb.org/browse/SERVER-127280 |
| url | https://jira.mongodb.org/browse/SERVER-127357 |
| url | https://jira.mongodb.org/browse/SERVER-127566 |
| url | https://jira.mongodb.org/browse/SERVER-127661 |
| url | https://jira.mongodb.org/browse/SERVER-127689 |
| url | https://jira.mongodb.org/browse/SERVER-127694 |
| url | https://jira.mongodb.org/browse/SERVER-127737 |
| url | https://jira.mongodb.org/browse/SERVER-127831 |
| url | https://jira.mongodb.org/browse/SERVER-128198 |
| url | https://jira.mongodb.org/browse/SERVER-128316 |
| url | https://jira.mongodb.org/browse/SERVER-128341 |
| url | https://jira.mongodb.org/browse/SERVER-128362 |
| url | https://jira.mongodb.org/browse/SERVER-128387 |
| url | https://jira.mongodb.org/browse/SERVER-128433 |
| url | https://jira.mongodb.org/browse/SERVER-128473 |
| url | https://jira.mongodb.org/browse/SERVER-128494 |
| url | https://jira.mongodb.org/browse/SERVER-128512 |
| url | https://jira.mongodb.org/browse/SERVER-128517 |
| url | https://jira.mongodb.org/browse/SERVER-128584 |
| url | https://jira.mongodb.org/browse/SERVER-128832 |
| url | https://jira.mongodb.org/browse/SERVER-129103 |
| url | https://github.com/mongodb-js/compass/releases/tag/v1.49.7 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13055 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13056 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13057 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13058 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13059 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13060 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13061 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13062 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13063 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13064 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13065 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13066 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13067 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13068 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13069 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13070 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13071 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13072 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13073 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13074 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13075 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13076 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13077 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-13078 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-14881 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-9737 |