# ANSSI Flags Multiple MongoDB Driver Vulnerabilities

Published: 2026-09-07 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/01656125-28ec-5cef-83f6-dd61fcfcd6f9/anssi-flags-multiple-mongodb-driver-vulnerabilities

> ANSSI advisory details 10 CVEs across MongoDB C, C++, and PHP drivers, libmongocrypt, and the VS Code extension, risking data confidentiality, integrity, and CSRF attacks.

ANSSI (French CERT) published an advisory covering multiple vulnerabilities discovered in MongoDB's ecosystem, affecting the C Driver (versions 2.x prior to 2.5.2 and versions prior to 1.30.9), C++ Driver (prior to 4.5.2), libmongocrypt (prior to 1.20.4), the MongoDB extension for VS Code (prior to 1.17.1), and the PHP Driver (versions 2.1.x prior to 2.1.9, 2.2.x prior to 2.5.1, and prior to 1.21.8).

The vulnerabilities collectively enable an attacker to compromise data confidentiality, compromise data integrity, bypass security policy, cause denial of service, and conduct cross-site request forgery (CSRF) via illegitimate rebound requests. Ten CVEs (CVE-2026-84962 through CVE-2026-84971) were assigned, corresponding to MongoDB's internal tracking tickets (CDRIVER, CXX, MONGOCRYPT, PHPC, VSCODE). No indication of active exploitation is provided; this is a routine vendor-coordinated disclosure with patches available. Organizations using affected MongoDB drivers or tooling should consult the referenced MongoDB security bulletins and update to the fixed versions.

## Mentioned in this report

- Vulnerabilities: CVE-2026-84962, CVE-2026-84963, CVE-2026-84964, CVE-2026-84965, CVE-2026-84966, CVE-2026-84967, CVE-2026-84968, CVE-2026-84969, CVE-2026-84970, CVE-2026-84971

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1123

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/01656125-28ec-5cef-83f6-dd61fcfcd6f9/anssi-flags-multiple-mongodb-driver-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
