Skip to content
Threat Feed
medium threat exploited

Multiple Vulnerabilities in MongoDB Core Server and Compass

Numerous vulnerabilities across MongoDB Core Server and Compass, identified as CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, enable attackers to bypass security policies and induce denial-of-service conditions, necessitating immediate patching.

CERT-FR has issued an advisory regarding multiple vulnerabilities discovered in MongoDB products, specifically affecting MongoDB Core Server and MongoDB Compass. These 26 distinct vulnerabilities, ranging from CVE-2026-13055 to CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, were initially detailed in MongoDB security bulletins on July 22, 2026. While no specific threat actor or active exploitation campaign has been identified, these flaws pose significant risks. Attackers could leverage these vulnerabilities to circumvent security policies, trigger denial-of-service (DoS) conditions, and exploit other unspecified security problems. Organizations using affected versions of MongoDB should prioritize applying the recommended patches to mitigate potential risks to their data and service availability.

Impact

Successful exploitation of these vulnerabilities could lead to significant damage. An attacker could bypass existing security policies, potentially gaining unauthorized access to sensitive data or functionality within the MongoDB environment. The denial-of-service vulnerabilities could allow an attacker to disrupt the availability of MongoDB databases and applications relying on them, leading to operational outages and financial losses. Furthermore, the presence of "unspecified security issues" suggests that other, potentially more severe, impacts may be possible depending on the specific vulnerability and how it is exploited, including data corruption or unauthorized data modification.

Recommendation

  • Refer to the MongoDB security bulletins referenced in this brief (e.g., SERVER-123081, SERVER-124355) and apply all necessary patches to update affected MongoDB Core Server and Compass instances to the patched versions.
  • Patch CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737 on all affected MongoDB installations immediately.
  • Ensure that MongoDB Compass is updated to version 1.49.7 or later.
  • Upgrade MongoDB Core Server to versions 7.0.39 or later, 8.0.28 or later, 8.2.12 or later, or 8.3.7 or later, depending on the major version deployed.

Indicators of compromise

52

url

TypeValue
urlhttps://jira.mongodb.org/browse/SERVER-123081
urlhttps://jira.mongodb.org/browse/SERVER-124355
urlhttps://jira.mongodb.org/browse/SERVER-125872
urlhttps://jira.mongodb.org/browse/SERVER-126247
urlhttps://jira.mongodb.org/browse/SERVER-127280
urlhttps://jira.mongodb.org/browse/SERVER-127357
urlhttps://jira.mongodb.org/browse/SERVER-127566
urlhttps://jira.mongodb.org/browse/SERVER-127661
urlhttps://jira.mongodb.org/browse/SERVER-127689
urlhttps://jira.mongodb.org/browse/SERVER-127694
urlhttps://jira.mongodb.org/browse/SERVER-127737
urlhttps://jira.mongodb.org/browse/SERVER-127831
urlhttps://jira.mongodb.org/browse/SERVER-128198
urlhttps://jira.mongodb.org/browse/SERVER-128316
urlhttps://jira.mongodb.org/browse/SERVER-128341
urlhttps://jira.mongodb.org/browse/SERVER-128362
urlhttps://jira.mongodb.org/browse/SERVER-128387
urlhttps://jira.mongodb.org/browse/SERVER-128433
urlhttps://jira.mongodb.org/browse/SERVER-128473
urlhttps://jira.mongodb.org/browse/SERVER-128494
urlhttps://jira.mongodb.org/browse/SERVER-128512
urlhttps://jira.mongodb.org/browse/SERVER-128517
urlhttps://jira.mongodb.org/browse/SERVER-128584
urlhttps://jira.mongodb.org/browse/SERVER-128832
urlhttps://jira.mongodb.org/browse/SERVER-129103
urlhttps://github.com/mongodb-js/compass/releases/tag/v1.49.7
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13055
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13056
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13057
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13058
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13059
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13060
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13061
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13062
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13063
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13064
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13065
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13066
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13067
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13068
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13069
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13070
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13071
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13072
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13073
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13074
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13075
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13076
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13077
urlhttps://www.cve.org/CVERecord?id=CVE-2026-13078
urlhttps://www.cve.org/CVERecord?id=CVE-2026-14881
urlhttps://www.cve.org/CVERecord?id=CVE-2026-9737