[Git][security-tracker-team/security-tracker][master] Add new batch of monbodb issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 24 22:17:22 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d8f70864 by Salvatore Bonaccorso at 2026-07-24T23:16:34+02:00
Add new batch of monbodb issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1448,53 +1448,77 @@ CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does no
 CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature v ...)
 	NOT-FOR-US: OIDC::Lite Perl module
 CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the server-side ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128832
 CVE-2026-13077 (A missing bounds check in the BSON CodeWScope element accessors allows ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-129103
 CVE-2026-13076 (An authenticated user can cause a {{mongod}} process to be terminated  ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128584
 CVE-2026-13075 (An authenticated user can cause the mongod process to be terminated by ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128316
 CVE-2026-13074 (An unauthenticated remote client can cause excessive CPU consumption o ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128517
 CVE-2026-13073 (An authenticated user with read-only privileges can cause the mongod p ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128512
 CVE-2026-13072 (When compute mode is enabled on a standalone mongod instance, insuffic ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128494
 CVE-2026-13071 (An authenticated user with read access can cause the mongod process to ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128473
 CVE-2026-13070 (A MongoDB server initiating an outbound TLS connection may terminate a ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128362
 CVE-2026-13069 (An authenticated user can cause excessive CPU consumption or out-of-me ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-127566
 CVE-2026-13068 (An authenticated user holding cursor termination privileges on one dat ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128198
 CVE-2026-13067 (When PROXY protocol v2 is used on the Unix domain socket path, roles d ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128387
 CVE-2026-13066 (Improper handling of DBPointer objects during BSON serialization in Mo ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-127694
 CVE-2026-13065 (A user with read-only privileges is able to craft an aggregation pipel ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-127280
 CVE-2026-13064 (Certain query operations involving deeply nested $jsonSchema construct ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-125872
 CVE-2026-13063 (An authenticated user with standard read/write privileges can cause th ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-127737
 CVE-2026-13062 (An authenticated user with write privileges on a Queryable Encryption- ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-127831
 CVE-2026-13061 (An authenticated user may be able to view session metadata belonging t ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-127689
 CVE-2026-13060 (An authenticated user with limited read privileges may be able to acce ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-127357
 CVE-2026-13059 (An authenticated user with low privileges may be able to perform unaut ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-128433
 CVE-2026-13058 (An authenticated user with basic write privileges can cause the mongod ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-127661
 CVE-2026-13057 (An issue in the server\u2019s Atlas Search integration allows an authe ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-126247
 CVE-2026-13056 (Using expressions that generate large arrays it is possible to craft a ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-124355
 CVE-2026-13055 (The `$_internalIndexKey` aggregation expression can be used by any aut ...)
-	TODO: check
+	- mongodb <removed>
+	NOTE: https://jira.mongodb.org/browse/SERVER-123081
 CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not perform auth ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows attackers to  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8f70864db802cdaf0547cf99d21d6c59a228b73

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8f70864db802cdaf0547cf99d21d6c59a228b73
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/21f47cef/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list