NoSQL Expression Injection Vulnerability in MongoDB C# Driver
CVE-2026-81527

6.9MEDIUM

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81527?

This vulnerability affects the LINQ-to-aggregation query translation layer in the MongoDB C# Driver. It arises when user-supplied values are inserted into specific query constructs without proper escaping. As a result, malicious users may manipulate these values, leading the database to interpret parts of the input as executable query logic rather than as raw data. Consequently, this could enable unauthorized access to sensitive information or altered query results, thereby posing a significant security risk to applications utilizing the affected driver.

Affected Version(s)

C# Driver 2.14.0 < 3.11.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.