MongoBleed Vulnerability Exposes MongoDB Data to Attackers

MongoBleed Vulnerability Exposes MongoDB Data to Attackers

First seen 10 Jan 2026, 10:51 UTC InfoqUnit42.Paloaltonetworks 52.9

Article Content

Browse articles
ThreatCluster

MongoDB has patched CVE-2025-14847, a vulnerability that affects multiple versions of MongoDB Server. The flaw allows unauthenticated attackers to remotely exploit the vulnerability with low complexity, potentially leading to the exfiltration of sensitive data and credentials. The vulnerability has been dubbed 'MongoBleed' in reference to the infamous Heartbleed bug.

Ask AI about this cluster