CVE-2026-81520
CVE-2026-81520 is a high-severity vulnerability in Mongodb Bi Connector with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1088.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v4: 8.7
- EPSS exploit prediction: 0% (34th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1088
- Affected product: Mongodb Bi Connector
- Published:
- Last modified:
Description
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each such session retains a worker, a client connection slot, and its associated backend database connections until the process is restarted. Repeated use of this behavior can consume the configured connection capacity and prevent legitimate users from establishing new sessions.
Frequently asked questions
- What is CVE-2026-81520?
- A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each such session retains a worker, a client connection slot, and its associated backend database connections until the process is restarted. Repeated use of this behavior can consume the configured connection capacity and prevent legitimate users from establishing new sessions.
- How severe is CVE-2026-81520?
- CVE-2026-81520 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2026-81520 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (34th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-81520?
- CVE-2026-81520 affects Mongodb Bi Connector. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-81520?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-81520 published?
- CVE-2026-81520 was published on 2026-08-28 and last updated on 2026-09-29.
References
Affected products (1)
- cpe:2.3:a:mongodb:bi_connector:*:*:*:*:*:*:*:*
More vulnerabilities in Mongodb Bi Connector
- CVE-2026-77586 — High (CVSS 8.0): In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted…
- CVE-2026-81490 — High (CVSS 7.7): A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the…
- CVE-2026-81518 — High (CVSS 7.5): When mongosqld is configured with a client certificate authority file, the listener requests a client certificate…
- CVE-2026-81517 — High (CVSS 7.5): An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough…
- CVE-2026-75159 — Medium (CVSS 5.9): An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication…
- CVE-2026-77184 — Medium (CVSS 5.2): In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the…
All CVEs affecting Mongodb Bi Connector →
Other CWE-1088 vulnerabilities
- CVE-2024-8062 — High (CVSS 7.5): A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint…
- CVE-2024-8061 — High (CVSS 7.5): In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts,…
- CVE-2024-12777 — Medium (CVSS 5.9): A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client.…
- CVE-2020-14483 — Medium (CVSS 4.3): A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread…
- CVE-2025-4656 — Low (CVSS 3.1): Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to…