« Volver al listado

Mongodb

Mongodb BI Connector: vulnerabilidades y CVE

Mongodb BI Connector tiene 8 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses8
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-81520Alta (8.7)0.42%—28 ago 2026
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because…
CVE-2026-81518Alta (8.7)0.25%—28 ago 2026
When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still…
CVE-2026-81517Alta (8.7)0.46%—28 ago 2026
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log…
CVE-2026-81490Alta (8.3)0.42%—28 ago 2026
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic…
CVE-2026-77586Alta (8.5)0.42%—28 ago 2026
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier…
CVE-2026-77184Media (5.7)0.30%—28 ago 2026
In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment text of the DDL returned by SHOW CREATE statements without complete escaping of backslash…
CVE-2026-75573Media (4.1)0.10%—27 ago 2026
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with…
CVE-2026-75159Alta (8.2)0.28%—27 ago 2026
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1005 Data from Local System1
  3. T1203 Exploitation for Client Execution1
  4. T1210 Exploitation of Remote Services1
  5. T1499 Endpoint Denial of Service1
  6. T1499.001 OS Exhaustion Flood1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Mongodb