

Threat Brief: MongoDB Vulnerability (CVE-2025-14847)
Published:
13 January 2026 at 20:30:02
Alert date:
13 January 2026 at 22:01:39
Source:
unit42.paloaltonetworks.com
Database & Storage
MongoDB disclosed CVE-2025-14847, nicknamed MongoBleed, which is an unauthenticated memory disclosure vulnerability. The vulnerability has a high CVSS score of 8.7, indicating significant security impact. This is a memory disclosure issue that affects the MongoDB database platform. The vulnerability allows unauthenticated attackers to potentially access sensitive information from memory. Given the high CVSS score and the nature of the vulnerability affecting a widely-used database platform, this represents a significant security concern for organizations using MongoDB.
Technical details
Mitigation steps:
Affected products:
MongoDB
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.

