VDB
CVE-2026-81524
CVE-2026-81524
PUBLISHED
CVSS 5.3 MEDIUM
Reported by mongodb · Published August 27, 2026
A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.
Risk Scores
CVSS 4.0
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| MongoDB | C Driver | 1.0.0 |
| MongoDB | C Driver | 1.0.0, 1.0.0 |
Timeline
- Aug 27, 2026 Coalition ESS Score
- Aug 27, 2026 CVE Published
- Aug 28, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 17, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 3, 2026 EPSS Score
- Oct 7, 2026 EPSS Score