
[CIVN-2026-0157] Multiple Vulnerabilities in MongoDB
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in MongoDB
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
MongoDB 8.2 versions prior to 8.2.6
MongoDB 8.0 versions prior to 8.0.20
MongoDB 7.0 versions prior to 7.0.31
Overview
Multiple vulnerabilities have been reported in MongoDB, which could allow an attacker to access sensitive information on the targeted system.
Target Audience:
All end-user organizations and individuals using MongoDB.
Risk Assessment:
High risk of unauthorized access to sensitive information.
Impact Assessment:
Potential for unauthorized access and information disclosure.
Description
MongoDB is a document-based database that stores information in flexible, JSON-like documents rather than traditional tables and rows, making it well suited for handling large or evolving data structures.
Multiple vulnerabilities exist in MongoDB due to Use-after-free in the classic engine $lookup and $graphLookup aggregation operators and stack memory disclosure in specially crafted filemd5 command.
Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.mongodb.com/resources/products/alerts#security
Vendor Information
MongoDB
https://www.mongodb.com/resources/products/alerts#security
References
MongoDB
https://jira.mongodb.org/browse/SERVER-119319
https://jira.mongodb.org/browse/SERVER-119317
CVE Name
CVE-2026-4147
CVE-2026-4148
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmnD9poACgkQ3jCgcSdc
ys+aAQ/5AYmHSc3dUI2ts6D5Hta6npeVXRT5KveeaukNixpMomn+jnQ5Y4bUco1J
8EopPzSoCw2Twje9pQzR1c+WCJB3UiovDHDvSGOm9z5XG/2nUxNSp7zWCCtTk4VB
N4cNZQpUNDO2ZrdYtnf7vQMtkpxnasKdkfe4o3T622Cj8NG9l90MIXqi75zKFmPo
5oVuTE1YEK3uOmlygMtGlz0cpmDxcVOTo+jWJgs8QI1nkdZuo2Uu1YaE+tIGea2j
x3qan1WBpX/K/LqLKPv4qvLnMA3eV+zOEAodX5i0AKufEpfUIz3xuwMKNRwgKgjl
6dpDCNm3enGEeNypLQP3HNNhEMOsMCRyAGAeZnhHliW0bnIehY3xeErubPpa/HXJ
OymGY7y9pbym1qP4na4RkVZyUVwqAhKwkLB6As799KRPU9mpnq+XMFMpGsKTG60t
DrGPo992Qx4qVqSW8iwtIP6GA9FPn1wf48A87Rh+tT3k0frgZZ788OLIcdI1Xcgr
9b6ng+Sray4TsPSFj3+IsXz19U7s67ZchvxgGNeP8XdOh7VnEeaaX1AXQPP6lASS
cwdtiEX0gQPkfr1smG5CuWbkw0DrX3NwIlR5xye5iDWazlDvgY9kmQwNKw3YVB8o
8O3vWZ5vIWYDD4TYi9RCHAe0AwkLtyUtV1uVGIXgLlGiO7uidNE=
=6ia1
—–END PGP SIGNATURE—–


