VORANT. Threat Intelligence Sign in Get the full feed

ANSSI Flags Multiple MongoDB Driver Vulnerabilities

routine vulnerability technology

ANSSI advisory details 10 CVEs across MongoDB C, C++, and PHP drivers, libmongocrypt, and the VS Code extension, risking data confidentiality, integrity, and CSRF attacks.

ANSSI (French CERT) published an advisory covering multiple vulnerabilities discovered in MongoDB's ecosystem, affecting the C Driver (versions 2.x prior to 2.5.2 and versions prior to 1.30.9), C++ Driver (prior to 4.5.2), libmongocrypt (prior to 1.20.4), the MongoDB extension for VS Code (prior to 1.17.1), and the PHP Driver (versions 2.1.x prior to 2.1.9, 2.2.x prior to 2.5.1, and prior to 1.21.8).

The vulnerabilities collectively enable an attacker to compromise data confidentiality, compromise data integrity, bypass security policy, cause denial of service, and conduct cross-site request forgery (CSRF) via illegitimate rebound requests. Ten CVEs (CVE-2026-84962 through CVE-2026-84971) were assigned, corresponding to MongoDB's internal tracking tickets (CDRIVER, CXX, MONGOCRYPT, PHPC, VSCODE). No indication of active exploitation is provided; this is a routine vendor-coordinated disclosure with patches available. Organizations using affected MongoDB drivers or tooling should consult the referenced MongoDB security bulletins and update to the fixed versions.

Mentioned in this report

Vulnerabilities CVE-2026-84962CVE-2026-84963CVE-2026-84964CVE-2026-84965CVE-2026-84966CVE-2026-84967CVE-2026-84968CVE-2026-84969CVE-2026-84970CVE-2026-84971

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1123

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free