CVE-2026-81520

CVE-2026-81520 is a high-severity vulnerability in Mongodb Bi Connector with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1088.

Key facts

Description

A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each such session retains a worker, a client connection slot, and its associated backend database connections until the process is restarted. Repeated use of this behavior can consume the configured connection capacity and prevent legitimate users from establishing new sessions.

Frequently asked questions

What is CVE-2026-81520?
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each such session retains a worker, a client connection slot, and its associated backend database connections until the process is restarted. Repeated use of this behavior can consume the configured connection capacity and prevent legitimate users from establishing new sessions.
How severe is CVE-2026-81520?
CVE-2026-81520 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
Is CVE-2026-81520 being actively exploited?
It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (34th percentile), an estimate of the probability of exploitation in the next 30 days.
What products are affected by CVE-2026-81520?
CVE-2026-81520 affects Mongodb Bi Connector. See the affected-products list for the exact vulnerable versions.
How do I fix CVE-2026-81520?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
When was CVE-2026-81520 published?
CVE-2026-81520 was published on 2026-08-28 and last updated on 2026-09-29.

References

Affected products (1)

More vulnerabilities in Mongodb Bi Connector

All CVEs affecting Mongodb Bi Connector →

Other CWE-1088 vulnerabilities

Browse all CWE-1088 vulnerabilities →