MongoDB disclosed multiple vulnerabilities in MongoDB Server and the MongoDB Java Driver, including one critical issue and at least 16 high-severity flaws that can lead to remote code execution, information disclosure, authentication bypass, data manipulation, and denial of service. National cyber agencies in Italy, Canada, and Guyana published advisories urging organizations to review MongoDB’s security bulletins and update affected deployments.
A key server-side issue, CVE-2026-18691 / SERVER-130264, affects intra-cluster SASL egress connection setup and can allow an attacker with adjacent network access to downgrade authentication to PLAIN, exposing a cleartext keyfile and potentially enabling authentication as MongoDB’s internal superuser. Advisories say the server flaw affects versions before 7.0.40, 8.0.29, 8.2.13, 8.3.8, and 9.0.0-rc2, while the Java Driver issue JAVA-6266 affects versions 4.11.0 through 5.9.1 and can expose a proxy password through ProxySettings.toString; administrators are advised to upgrade to patched releases immediately.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
On August 12, 2026, multiple national cybersecurity bodies published notices warning about MongoDB Server and Java Driver vulnerabilities, including one critical and multiple high-severity issues. The notices identified affected version ranges and advised users and administrators to review MongoDB's bulletins and update to fixed releases.
MongoDB published a security advisory on August 11, 2026 describing vulnerabilities affecting MongoDB Driver and multiple MongoDB Server branches. The advisory included SERVER-130264, which can enable a downgrade to the PLAIN SASL mechanism and expose a cleartext keyfile, and JAVA-6266, involving failure to mask a proxy password in ProxySettings.toString.
On August 11, 2026, a new CVE entry, CVE-2026-18691, was recorded for a MongoDB Server vulnerability in intra-cluster connection setup. The flaw could allow an attacker with adjacent network access to influence authentication between replica set members and potentially recover the cluster's shared internal credential.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourceacn.gov.it
Open sourcecirt.gy
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.