MongoDB C Driver Vulnerability Exposes Applications to Unsanitized Input Risks
CVE-2026-81524

5.3MEDIUM

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81524?

A vulnerability in the MongoDB C Driver allows user-supplied input for database and collection names to bypass necessary sanitization. This flaw can direct operations to unintended resources if an application incorporates untrusted data into these name components. As a result, attackers could exploit this weakness, leading to unauthorized access and potential manipulation of sensitive database records.

Affected Version(s)

C Driver 1.0.0 < 2.5.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.