ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security

MongoDB security advisory (AV26-918)

lowAdvisoryimportance 20
AI summary · glm-5.3

Canadian Cyber Centre advisory AV26-918 urges patching MongoDB Server vulnerability fixed in 7.0.43, 8.0.32, 8.3.11, and 9.0.1.

The Canadian Centre for Cyber Security issued advisory AV26-918 on September 14, 2026, regarding a vulnerability in MongoDB Server. Affected versions include those prior to 7.0.43, 8.0.32, 8.3.11, 9.1.0-rc0, and 9.0.1. The fix shreds collection validator constants during parsing. Users and administrators are encouraged to review MongoDB's advisory and apply updates as they become available.

  • Advisory AV26-918 issued September 14, 2026 by the Canadian Cyber Centre
  • Affects MongoDB Server prior to 7.0.43, 8.0.32, 8.3.11, 9.1.0-rc0, 9.0.1
  • Fix shreds collection validator constants during parsing
  • No CVE identifier or exploitation activity stated
Full article70 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-918
Date: September 14, 2026

As of September 11, 2026, MongoDB is affected by a vulnerability in the following product:

  • MongoDB Server
    • Prior to 7.0.43
    • Prior to 8.0.32
    • Prior to 8.3.11
    • Prior to 9.1.0-rc0
    • Prior to 9.0.1

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/mongodb-security-advisory-av26-918