CVE-2026-81521
CVE-2026-81521 is a medium-severity vulnerability in Mongodb Go Driver with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-99.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v4: 7.1
- EPSS exploit prediction: 0% (27th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-99
- Affected product: Mongodb Go Driver
- Published:
- Last modified:
Description
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.
Frequently asked questions
- What is CVE-2026-81521?
- The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.
- How severe is CVE-2026-81521?
- CVE-2026-81521 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2026-81521 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (27th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-81521?
- CVE-2026-81521 affects Mongodb Go Driver. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-81521?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-81521 published?
- CVE-2026-81521 was published on 2026-08-27 and last updated on 2026-10-06.
References
- https://jira.mongodb.org/browse/GODRIVER-4075
- https://pkg.go.dev/go.mongodb.org/mongo-driver/[email protected]
Affected products (1)
- cpe:2.3:a:mongodb:go_driver:*:*:*:*:*:mongodb:*:*
More vulnerabilities in Mongodb Go Driver
- CVE-2026-88031 — High (CVSS 8.1): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can…
- CVE-2021-20329 — Medium (CVSS 6.8): Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A…
All CVEs affecting Mongodb Go Driver →
Other CWE-99 vulnerabilities
- CVE-2025-43491 — Critical (CVSS 9.8): A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the…
- CVE-2017-5159 — Critical (CVSS 9.8): An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0. When updating an…
- CVE-2025-2410 — Critical (CVSS 9.1): Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if…
- CVE-2025-0756 — Critical (CVSS 9.1): Overview The product receives input from an upstream component, but it does not restrict or incorrectly…
- CVE-2024-57971 — Critical (CVSS 9.1): DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that…
- CVE-2024-5706 — High (CVSS 8.8): The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input…