CVE-2026-81520CWE-1088

CVE-2026-81520

High · published August 29, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
14.8
In the wild
Unconfirmed
What it is

A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each such session retains a worker, a client connection slot, and its associated backend database connections until the process is restarted. Repeated use of this behavior can consume the configured connection capacity and prevent legitimate users from establishing new sessions.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00239 · 14.8th percentile
Weakness
CWE-1088 · Synchronous Access of Remote Resource without Timeout
Published
2026-08-29T02:16Z
References (1)
EPSS history
Timeline
  • 30 AUG 16:19Z
    EPSS moved — → 0%
    epss
  • 28 AUG 20:22Z
    MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaustion
    cvelistv5