[CLSA-2026:1776080798] Fix CVE(s): CVE-2026-25609
Type:
security
Severity:
Important
Release date:
2026-04-14 09:34:02 UTC
Description:
* SECURITY UPDATE: Fix missing authorization check for profile filter parameter - debian/patches/CVE-2026-25609.patch: Extract isReadOnly() function and add !request.getFilter() to the read-only check in profile command auth logic - CVE-2026-25609
Updated packages:
  • mongodb6_6.0.26-1+tuxcare.els5_amd64.deb
    sha:730dcfbeb2887741b5cdaa81086833f41efedb71
  • mongodb6-mongos_6.0.26-1+tuxcare.els5_amd64.deb
    sha:8bdc2b0790d6c01694cbe86276581ee459df5567
  • mongodb6-server_6.0.26-1+tuxcare.els5_amd64.deb
    sha:5ff24cd0dfef59b2dbce48d538e5b89c952f5e3c
  • mongodb6-shell_6.0.26-1+tuxcare.els5_amd64.deb
    sha:9429df94b795aadfd798c6a4af23dfe69329cd3d
  • mongodb6_6.0.26-1+tuxcare.els5_arm64.deb
    sha:d862b70b8bd50413faa3655bf3ef307dcb20f823
  • mongodb6-mongos_6.0.26-1+tuxcare.els5_arm64.deb
    sha:77cbe5b319bbe87a39bf65f346dc7d115bb8c40f
  • mongodb6-server_6.0.26-1+tuxcare.els5_arm64.deb
    sha:f3cc9666c7e640c071210f7e535742644db63cd0
  • mongodb6-shell_6.0.26-1+tuxcare.els5_arm64.deb
    sha:acb82c0300a06c60c9c65d5ad83d274078a70600
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.