MongoDB security advisory (AV26-911)
Brief
Serial Number: AV26-911
Date: September 11, 2026
As of September 10, 2026, MongoDB is affected by vulnerabilities in the following products:
- Java Driver
- Prior to 5.11.1
- Laravel MongoDB (PHP)
- Prior to 5.11.0
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- [PHPLARA-260] Query builder: force literal equality when 3-arg where uses '=' with an array value
- [JAVA-6276] Native heap use-after-free via cancellation racing KMS credential fetch in reactive encryption
- Alerts
- MongoDB
MongoDB security advisory (AV26-911) - Canadian Centre for Cyber Security
