VDB

CVE-2026-81524

CVE-2026-81524 PUBLISHED CVSS 5.3 MEDIUM

Reported by mongodb · Published August 27, 2026

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.

Risk Scores

CVSS 4.0
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
MongoDBC Driver1.0.0
MongoDBC Driver1.0.0, 1.0.0

Timeline

  • Aug 27, 2026 Coalition ESS Score
  • Aug 27, 2026 CVE Published
  • Aug 28, 2026 EPSS Score
  • Sep 2, 2026 Security Advisory
  • Sep 17, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
  • Oct 3, 2026 EPSS Score
  • Oct 7, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›