STIGQter STIGQter: STIG Summary: MongoDB Enterprise Advanced 7.x Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

Security-relevant software updates to MongoDB must be installed within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).

DISA Rule

SV-265972r1137667_rule

Vulnerability Number

V-265972

Group Title

SRG-APP-000456-DB-000390

Rule Version

MD7X-00-009200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Institute and adhere to the policies and procedures to ensure that MongoDB is updated consistent with the organizational or site-specific software update policy and time frame.

Update MongoDB to the necessary major and minor release in accordance with the organizational or site-specific policy.

Check Contents

Review the organizational or site-specific software update policy and verify that MongoDB has been updated consistent with the time frame specified by that policy.

The current patch release versions of MongoDB 7.0.x can be found here: https://www.mongodb.com/docs/manual/release-notes/7.0/

This link will show the patch release versions with the date of release for all of MongoDB 7.0.x.

If MongoDB has not been updated to the necessary major and minor release in accordance with the policy this is a finding.

Vulnerability Number

V-265972

Documentable

False

Rule Version

MD7X-00-009200

Severity Override Guidance

Review the organizational or site-specific software update policy and verify that MongoDB has been updated consistent with the time frame specified by that policy.

The current patch release versions of MongoDB 7.0.x can be found here: https://www.mongodb.com/docs/manual/release-notes/7.0/

This link will show the patch release versions with the date of release for all of MongoDB 7.0.x.

If MongoDB has not been updated to the necessary major and minor release in accordance with the policy this is a finding.

Check Content Reference

M

Target Key

5637