# MongoDB patches multiple Compass, Server flaws

Published: 2026-07-24 · Severity: medium
Canonical: https://vorant.io/reports/ea411b83-593e-5e03-82dc-cba13dd8bf21/mongodb-patches-multiple-compass-server-flaws

> CERT-FR advisory details multiple MongoDB Compass and Core Server vulnerabilities allowing security bypass and denial of service, with patches available.

CERT-FR issued an advisory covering numerous vulnerabilities affecting MongoDB Compass (versions prior to 1.49.7) and MongoDB Core Server across the 7.0.x, 8.0.x, 8.2.x, and 8.3.x branches. The vulnerabilities, tracked under more than 25 distinct CVE identifiers, allow attackers to bypass security policies, trigger denial-of-service conditions, and exploit an unspecified security issue as described by the vendor.

No evidence of active exploitation is mentioned in the advisory, and the recommended remediation is to apply the vendor-supplied patches referenced in MongoDB's own security bulletins and the Compass v1.49.7 release. Organizations running affected MongoDB deployments should prioritize patching per standard vulnerability management processes.

## Mentioned in this report

- Vulnerabilities: CVE-2026-13055, CVE-2026-13056, CVE-2026-13057, CVE-2026-13058, CVE-2026-13059, CVE-2026-13060, CVE-2026-13061, CVE-2026-13062, CVE-2026-13063, CVE-2026-13064, CVE-2026-13065, CVE-2026-13066, CVE-2026-13067, CVE-2026-13068, CVE-2026-13069, CVE-2026-13070, CVE-2026-13071, CVE-2026-13072, CVE-2026-13073, CVE-2026-13074, CVE-2026-13075, CVE-2026-13076, CVE-2026-13077, CVE-2026-13078, CVE-2026-14881, CVE-2026-9737

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0922

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ea411b83-593e-5e03-82dc-cba13dd8bf21/mongodb-patches-multiple-compass-server-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
