Two MongoDB driver bugs are not confirmed code execution
CVE-2026-96748 lets an untrusted hostname add a server to a PyMongo client. CVE-2026-96746 can crash the C driver. Both are scored 8.3. Neither NVD text is arbitrary code execution, and neither is in the CISA catalog.
Published 5 Oct 2026
What happened
MongoDB’s driver update in late September 2026 covers more than one CVE. The two scores of 8.3 that the alert names are CVE-2026-96748 and CVE-2026-96746. NVD published both on 24 September 2026. They are different products and different outcomes.
CVE-2026-96748 is in PyMongo. Percent-encoded characters in the host part of a connection string are decoded before the host list is split. An untrusted hostname placed into that string can add servers the application did not intend. Those servers can see a limited authentication exchange and can return altered results. CWE-177. CVSS 4.0 score 8.3, with an attack requirement.
CVE-2026-96746 is in the MongoDB C driver. An out-of-bounds write in connection monitoring can fire when an unauthenticated party controls name resolution and the responses of the hosts already named in the connection string. NVD says the application may terminate. CWE-787. The score is also 8.3, and the high impact in the vector is availability.
Who is affected
PyMongo is affected before 4.18.2, and only when application code inserts a hostname it does not control into the connection string. A process with a fixed connection string is outside that sentence. The 4.18.2 notes also list CVE-2026-96747 and CVE-2026-96749. Those ids are not given records in this pass.
The C driver fixes NVD points to are 1.30.12 and 2.5.5. The attacker’s position is name resolution for the hosts the client already uses, not a normal database login.
What is confirmed
Both scores, both weakness ids, and both NVD descriptions are published. CISA’s catalog does not list either CVE. No public proof of concept was attached to either record. The status on both is No PoC. The same MongoDB note that says no active exploitation was reported matches the catalog check.
What is not confirmed
The alert says the vulnerabilities can, in some cases, allow arbitrary code execution. That sentence is not the NVD text for these two ids. CVE-2026-96748 is host injection and altered results. CVE-2026-96746 is a write that can crash the process. ThreatWire does not relabel either one as remote code execution to match the broader sentence. Other CVEs in the same driver update are not silently folded into these records.
What to do
Upgrade PyMongo to 4.18.2 or later where untrusted host data can reach a connection string. Upgrade the C driver to 1.30.12 on the 1.x line or 2.5.5 on the 2.x line. Compass, the PHP driver, and Laravel MongoDB were named in the alert and are not these two CVEs. They need their own advisories before they get records.
Sources: NVD for CVE-2026-96748 and CVE-2026-96746, the PyMongo 4.18.2 release and changelog, and the C driver tags 1.30.12 and 2.5.5.
Related CVEs
- CVE-2026-96748 — PyMongo connection-string host injection
- CVE-2026-96746 — MongoDB C driver connection-monitor overflow