MongoDB Server vulnerability

An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms. This could allow authentication through a method the administrator intended to disable.

Published 11 Aug 2026Updated 16 Sep 20261 sources
CVSS 2.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.