Client-Side Authentication Buffer Overflow in MongoDB C Driver
CVE-2026-88035

5.7MEDIUM

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88035?

A vulnerability exists in the MongoDB C Driver relating to client-side authentication where improper size checks can lead to a buffer overflow. Specifically, if a user provides an unusually large username, it can be accepted and subsequently copied beyond the bounds of a small buffer. This misconfiguration may allow an attacker with control over the driver's connection settings to manipulate the application using the driver, potentially causing it to terminate unexpectedly. This issue is particularly concerning when the optional external SASL authentication backend is utilized.

Affected Version(s)

C Driver 2.2.0 < 2.5.3

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.