MongoDB C++ Driver Vulnerability with NUL Byte Handling
CVE-2026-106430

6MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 October 2026

What is CVE-2026-106430?

The MongoDB C++ Driver has a flaw where it improperly handles embedded NUL bytes in field and collection names. This vulnerability may allow an authenticated user to manipulate the naming convention, leading the application to treat one name as another. This can result in unauthorized access to unintended fields or collections, potentially compromising data integrity and security. The issue arises when the specific content in the naming structure is discarded, causing discrepancies between expected and actual operations.

Affected Version(s)

C++ Driver 3.0.0 < 4.6.1

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.