Cyber Resilience
← All news

MongoDB security advisory (AV26-744)

CCCS relays MongoDB advisories for Compass before 1.49.7 and Server before 7.0.39, 8.0.28, 8.2.12, 8.3.7. Update Compass if you use it; patch Server only if you self-host — Atlas customers can skip the server side.
Sources (1)
What this means for you — CISO:If you run self-hosted MongoDB Server or Compass, patch to the fixed versions in the advisory (Compass 1.49.7+; Server 7.0.39+, 8.0.28+, 8.2.12+, or 8.3.7+). Atlas and other hosted tenants are the provider’s responsibility—confirm your estate inventory either way.
What this means for you — Lean IT orgs:If you install MongoDB Server or Compass yourself, update to the versions in the advisory now. If you only use a hosted MongoDB service, the provider patches the server; still update Compass if you run it locally.
What this means for you — MSP:Inventory clients for self-hosted MongoDB Server and Compass and push Compass 1.49.7+ and Server 7.0.39+ / 8.0.28+ / 8.2.12+ / 8.3.7+. Note Atlas-only clients separately so you don’t burn cycles on provider-managed nodes.
What this means for you — Researcher:CCCS AV26-744 tracks MongoDB’s 22 Jul 2026 fixes for Compass prior to 1.49.7 and Server prior to 7.0.39, 8.0.28, 8.2.12, and 8.3.7—pull the vendor advisories for CVE detail and affected configurations.