CVE-2026-81524
CVE-2026-81524 is a medium-severity vulnerability in Mongodb C Driver with a CVSS 3.x base score of 5.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-99.
Key facts
- Severity: Medium (CVSS 3.x base score 5.4)
- CVSS v4: 5.3
- EPSS exploit prediction: 0% (17th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-99
- Affected product: Mongodb C Driver
- Published:
- Last modified:
Description
A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.
Frequently asked questions
- What is CVE-2026-81524?
- A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.
- How severe is CVE-2026-81524?
- CVE-2026-81524 has a CVSS 3.x base score of 5.4, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-81524 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (17th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-81524?
- CVE-2026-81524 affects Mongodb C Driver. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-81524?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-81524 published?
- CVE-2026-81524 was published on 2026-08-27 and last updated on 2026-09-29.
References
- https://github.com/mongodb/mongo-c-driver/releases/tag/2.5.1
- https://jira.mongodb.org/browse/CDRIVER-6424
Affected products (1)
- cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*
More vulnerabilities in Mongodb C Driver
- CVE-2026-88036 — High (CVSS 8.3): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can…
- CVE-2026-93393 — High (CVSS 8.1): A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows…
- CVE-2026-6691 — High (CVSS 7.8): The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling…
- CVE-2024-7553 — High (CVSS 7.3): Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the…
- CVE-2025-12119 — Medium (CVSS 6.8): A mongoc_bulk_operation_t may read invalid memory if large options are passed.
- CVE-2026-84964 — Medium (CVSS 5.9): A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a…
All CVEs affecting Mongodb C Driver →
Other CWE-99 vulnerabilities
- CVE-2025-43491 — Critical (CVSS 9.8): A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the…
- CVE-2017-5159 — Critical (CVSS 9.8): An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0. When updating an…
- CVE-2025-2410 — Critical (CVSS 9.1): Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if…
- CVE-2025-0756 — Critical (CVSS 9.1): Overview The product receives input from an upstream component, but it does not restrict or incorrectly…
- CVE-2024-57971 — Critical (CVSS 9.1): DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that…
- CVE-2024-5706 — High (CVSS 8.8): The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input…