VORANT. Threat Intelligence Sign in Get the full feed

MongoDB patches multiple Compass, Server flaws

medium vulnerability

CERT-FR advisory details multiple MongoDB Compass and Core Server vulnerabilities allowing security bypass and denial of service, with patches available.

CERT-FR issued an advisory covering numerous vulnerabilities affecting MongoDB Compass (versions prior to 1.49.7) and MongoDB Core Server across the 7.0.x, 8.0.x, 8.2.x, and 8.3.x branches. The vulnerabilities, tracked under more than 25 distinct CVE identifiers, allow attackers to bypass security policies, trigger denial-of-service conditions, and exploit an unspecified security issue as described by the vendor.

No evidence of active exploitation is mentioned in the advisory, and the recommended remediation is to apply the vendor-supplied patches referenced in MongoDB's own security bulletins and the Compass v1.49.7 release. Organizations running affected MongoDB deployments should prioritize patching per standard vulnerability management processes.

Mentioned in this report

Vulnerabilities CVE-2026-13055CVE-2026-13056CVE-2026-13057CVE-2026-13058CVE-2026-13059CVE-2026-13060CVE-2026-13061CVE-2026-13062CVE-2026-13063CVE-2026-13064CVE-2026-13065CVE-2026-13066CVE-2026-13067CVE-2026-13068CVE-2026-13069CVE-2026-13070CVE-2026-13071CVE-2026-13072CVE-2026-13073CVE-2026-13074CVE-2026-13075CVE-2026-13076CVE-2026-13077CVE-2026-13078CVE-2026-14881CVE-2026-9737

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0922

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free