Every CVE whose affected-product data names Mongodb Bi Connector, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (8)
CVE-2026-77586 — CVSS 8.0 (high): In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the…
CVE-2026-81490 — CVSS 7.7 (high): A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop…
CVE-2026-81520 — CVSS 7.5 (high): A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by…
CVE-2026-81517 — CVSS 7.5 (high): An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection…
CVE-2026-81518 — CVSS 7.5 (high): When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake…
CVE-2026-75159 — CVSS 5.9 (medium): An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld…
CVE-2026-77184 — CVSS 5.2 (medium): In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment text of the DDL…
CVE-2026-75573 — CVSS 4.4 (medium): In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both…