MONGODB disclosed 27 vulnerabilities across MongoDB Server and Compass, with most being denial-of-service (DoS) bugs, and several allowing access-control bypass or information disclosure. The vulnerabilities include 1 critical (9.2), 19 high, and 7 medium severity, with no confirmed exploitation. Key vulnerabilities include CVE-2026-13072, which causes memory corruption, and CVE-2026-13059, which allows for role-based access control bypass.
Users are advised to apply the latest security updates and adopt mitigation steps to reduce risk. Notably, the server flaws impact release lines 7.0, 8.0, 8.2, and 8.3, while Compass users should upgrade to version 1.49.7 or later.