CVE-2026-6915: MongoDB

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account.

Affected products

  • MongoDB MongoDB: from 7.0.0, before 7.0.32 (fixed in 7.0.32); from 8.0.0, before 8.0.21 (fixed in 8.0.21); from 8.2.0, before 8.2.7 (fixed in 8.2.7)

Published 2026-04-29. Last modified 2026-06-17.