[CIVN-2026-0157] Multiple Vulnerabilities in MongoDB

By Published On: March 25, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in MongoDB


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


MongoDB 8.2 versions prior to 8.2.6

MongoDB 8.0 versions prior to 8.0.20

MongoDB 7.0 versions prior to 7.0.31

Overview


Multiple vulnerabilities have been reported in MongoDB, which could allow an attacker to access sensitive information on the targeted system.


Target Audience:

All end-user organizations and individuals using MongoDB.


Risk Assessment:

High risk of unauthorized access to sensitive information.


Impact Assessment:

Potential for unauthorized access and information disclosure.


Description


MongoDB is a document-based database that stores information in flexible, JSON-like documents rather than traditional tables and rows, making it well suited for handling large or evolving data structures.


Multiple vulnerabilities exist in MongoDB due to Use-after-free in the classic engine $lookup and $graphLookup aggregation operators and stack memory disclosure in specially crafted filemd5 command. 


Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://www.mongodb.com/resources/products/alerts#security



Vendor Information


MongoDB

https://www.mongodb.com/resources/products/alerts#security


References


MongoDB

https://jira.mongodb.org/browse/SERVER-119319

https://jira.mongodb.org/browse/SERVER-119317


CVE Name

CVE-2026-4147

CVE-2026-4148




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmnD9poACgkQ3jCgcSdc

ys+aAQ/5AYmHSc3dUI2ts6D5Hta6npeVXRT5KveeaukNixpMomn+jnQ5Y4bUco1J

8EopPzSoCw2Twje9pQzR1c+WCJB3UiovDHDvSGOm9z5XG/2nUxNSp7zWCCtTk4VB

N4cNZQpUNDO2ZrdYtnf7vQMtkpxnasKdkfe4o3T622Cj8NG9l90MIXqi75zKFmPo

5oVuTE1YEK3uOmlygMtGlz0cpmDxcVOTo+jWJgs8QI1nkdZuo2Uu1YaE+tIGea2j

x3qan1WBpX/K/LqLKPv4qvLnMA3eV+zOEAodX5i0AKufEpfUIz3xuwMKNRwgKgjl

6dpDCNm3enGEeNypLQP3HNNhEMOsMCRyAGAeZnhHliW0bnIehY3xeErubPpa/HXJ

OymGY7y9pbym1qP4na4RkVZyUVwqAhKwkLB6As799KRPU9mpnq+XMFMpGsKTG60t

DrGPo992Qx4qVqSW8iwtIP6GA9FPn1wf48A87Rh+tT3k0frgZZ788OLIcdI1Xcgr

9b6ng+Sray4TsPSFj3+IsXz19U7s67ZchvxgGNeP8XdOh7VnEeaaX1AXQPP6lASS

cwdtiEX0gQPkfr1smG5CuWbkw0DrX3NwIlR5xye5iDWazlDvgY9kmQwNKw3YVB8o

8O3vWZ5vIWYDD4TYi9RCHAe0AwkLtyUtV1uVGIXgLlGiO7uidNE=

=6ia1

—–END PGP SIGNATURE—–

 

Share this article