#MongoDB
All CosmicBytez Labs articles tagged #MongoDB, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-19001: MongoDB BI Connector ODBC Driver Buffer Overflow (CVSS 9.8)
Critical CVSS 9.8 buffer overflow in the MongoDB BI Connector ODBC Driver may allow remote code execution via long metadata names.
- Security
CVE-2026-45688: Rocket.Chat CAS Login MongoDB Operator Injection (CVSS 9.1)
Critical unauthenticated account takeover vulnerability in Rocket.Chat's CAS login handler passes unsanitized client input directly into a MongoDB findOne...
- Security
CVE-2026-45689: Rocket.Chat OAuth Token Hijack via MongoDB Operator Injection (CVSS 9.1)
Critical pre-authentication vulnerability in Rocket.Chat allows any unauthenticated network attacker to obtain a valid OAuth access token for an arbitrary...
- Security
CVE-2026-8053: MongoDB Time-Series Out-of-Bounds Write
An authenticated user with database write privileges can trigger an out-of-bounds memory write in the mongod process via a flaw in MongoDB Server's...
- News
IDMerit KYC Data Breach Exposes 1 Billion Records Across 26
An unprotected MongoDB instance belonging to identity verification firm IDMerit left over 1 billion personal records — including SSNs, passport numbers,...