Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-82070

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. The same credentials are properly redacted in server log output, but the diagnostic interface omits equivalent redaction. Successful exploitation requires a valid authenticated session with monitoring-level permissions and results in exposure of cleartext credentials that could enable impersonation of other users, including privileged accounts.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-82073

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are in use. The issue stems from insufficient validation of an internal command parameter that can be set by external clients, causing a security check to be improperly skipped.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-82074

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-82075

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router port and has not authenticated can supply connection-monitoring parameters that cause the server to expend CPU resources without any rate limiting, degrading or denying service to legitimate clients. No authentication, elevated privileges, or user interaction is required. Only availability is affected; data confidentiality and integrity are not impacted.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-82071

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process, causing a denial of service via server crash, with potential for further impact including arbitrary code execution.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-82514

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
08/09/2026

CVE-2026-82076

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal resource limit. Submitting a specially crafted query causes the server to consume memory without bound during query planning, and the resulting exhaustion terminates the server process. This may result in a denial of service affecting all databases served by the affected node.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-82533

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies to unconfined execution, and retrieve all stored conversations without any credential or API key.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
08/09/2026

CVE-2026-82063

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing conditions during cursor operations, a stale pointer to a freed resource may be retained and subsequently dereferenced during cursor cleanup, leading to a server process crash.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/09/2026

CVE-2026-82064

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authentication, and the assertion's assumptions about internal state do not hold for all member configurations, causing the server process to terminate.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-82065

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of service. Insufficient validation of user-supplied storage configuration options permits values that, once persisted to durable metadata, trigger a fatal assertion failure when the metadata is subsequently read by diagnostic operations. The corrupted metadata persists across server restarts and is replicated to other cluster members, requiring manual operator intervention to restore service.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-82066

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can trigger the security issue through crafted query operations, causing the server to read memory beyond allocated buffer boundaries. The revealed memory contents may be partially observable through diagnostic query statistics output.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/09/2026