MongoDB Go Driver Bulk Write Operation Vulnerability
CVE-2026-81521

7.1HIGH

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81521?

The MongoDB Go Driver contains a vulnerability in its Client.BulkWrite API, which can be exploited if an application passes user-supplied database names that contain reserved separator characters. This flaw allows the construction of a target namespace that may not correspond to the intended database, potentially redirecting writes to unexpected locations. Developers must ensure that input validation and sanitization are thoroughly implemented to prevent untrusted inputs from compromising data integrity.

Affected Version(s)

GO Driver 2.1.0 < 2.8.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.