<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:24:06.535406+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-mongodb-2026-82073</id>
    <title>BIT-mongodb-2026-82073 — Improper Validation in MongoDB Server Aggregation Framework Allows Authorization Bypass and Unauthorized Collection Acc…</title>
    <updated>2026-10-03T04:24:06.607100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: mongodb</p>
<p>A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are in use. The issue stems from insufficient validation of an internal command parameter that can be set by external clients, causing a security check to be improperly skipped.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-mongodb-2026-82073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1157</id>
    <title>certfr-2026-avi-1157 — De multiples vulnérabilités ont été découvertes dans MongoDB Server. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-03T04:24:06.607157+00:00</updated>
    <content>certfr-2026-avi-1157</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-365256</id>
    <title>EUVD-2026-365256</title>
    <updated>2026-10-03T04:24:06.607177+00:00</updated>
    <content>EUVD-2026-365256</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-365256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-82073</id>
    <title>fkie_cve-2026-82073</title>
    <updated>2026-10-03T04:24:06.607189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are in use. The issue stems from insufficient validation of an internal command parameter that can be set by external clients, causing a security check to be improperly skipped.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-82073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r24j-5hx2-2mx8</id>
    <title>GHSA-r24j-5hx2-2mx8</title>
    <updated>2026-10-03T04:24:06.607211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are in use. The issue stems from insufficient validation of an internal command parameter that can be set by external clients, causing a security check to be improperly skipped.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r24j-5hx2-2mx8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82073</id>
    <title>UBUNTU-CVE-2026-82073</title>
    <updated>2026-10-03T04:24:06.607242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: mongodb, Ubuntu:Pro:16.04:LTS: mongodb, Ubuntu:Pro:18.04:LTS: mongodb, Ubuntu:Pro:20.04:LTS: mongodb</p>
<p>A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are in use. The issue stems from insufficient validation of an internal command parameter that can be set by external clients, causing a security check to be improperly skipped.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3236</id>
    <title>WID-SEC-W-2026-3236 — MongoDB Server: Mehrere Schwachstellen</title>
    <updated>2026-10-03T04:24:06.607267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in MongoDB Server ausnutzen, um erweiterte Berechtigungen, einschließlich Administratorrechte, zu erlangen und beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3236"/>
  </entry>
</feed>
