MongoDB security advisory (AV26-810)
Brief
Serial number: AV26-810 Date: August 12, 2026
As of August 11, 2026, MongoDB is affected by vulnerabilities in the following products:
- MongoDB Driver
- Prior to 5.9.2
- MongoDB Server
- Prior to 7.0.40
- Prior to 8.0.29
- Prior to 8.2.13
- Prior to 8.3.8
- Prior to 9.0.0-rc2
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- [SERVER-130264] Intra-cluster SASL mechanism allow list missing in egress connection setup, enabling PLAIN downgrade and cleartext keyfile disclosure - MongoDB Jira
- [JAVA-6266] Mask proxy password in ProxySettings toString - MongoDB Jira
- Alerts
- MongoDB
MongoDB security advisory (AV26-810) - Canadian Centre for Cyber Security
