Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/mongodb/ops-manager

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-87109 is a vulnerability in MongoDB Ops Manager that allows an authenticated organization member to access another member's pending authenticator enrollment seed if that enrollment is unconfirmed. This exposure occurs through user-listing endpoints and results in disclosure of secret authentication material within the same organization or project.

Join the discussion

CVE-2026-87108 is an authorization bypass vulnerability in MongoDB Ops Manager. An authenticated user with a read-only project role can access daily host monitoring records from other projects if they have the record identifier. This occurs due to insufficient ownership validation, potentially exposing deployment metadata such as host and configuration details. The vulnerability affects Ops Manager versions from 7.0.0 up to and including 7.0.23, and from 8.0.0 up to but not including 8.0.27. The CVSS 4.0 base score is 2.3, indicating low severity.

Join the discussion

CVE-2026-87110 is a vulnerability in MongoDB Ops Manager where an unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform resource-intensive operations without any rate limiting. This can cause temporary slowdowns of other traffic handled by the same process. The vulnerability affects versions 7.0.0 through 7.0.23 and 8.0.0 through 8.0.26. It has a medium severity rating with a CVSS score of 6.9.

Join the discussion

An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.  This issue affects all MongoDB Ops Manager 7.0 versions and MongoDB Ops Manager versions 8.0.22 and prior.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/mongodb/ops-manager
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses