CVE Tools

MongoDB Server Vulnerability Wave Hits Document Databases

Daily CyberSecurity (securityonline.info)By Do Son

PatchMongoDB

Our summary

MongoDB Server has disclosed a new set of security issues affecting document databases, with fixes covering several MongoDB release lines (including 7.0, 8.0, 8.2, and 8.3). The advisories include CVE-2026-11933 (use-after-free in server-side JavaScript that can leak memory or crash when reachable by an authenticated user), CVE-2026-9740 (an unauthenticated denial-of-service crash via BSON validation recursion), CVE-2026-9750 and CVE-2026-9743 (authenticated and aggregation-related crash or incorrect-results scenarios). Because at least one bug can be triggered without authentication, upgrading to the provided fixed versions such as 8.0.26, 8.2.11, and 8.3.4 is a priority.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store