CVE-2026-81524CWE-99

CVE-2026-81524

Medium · published August 28, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
5.1
In the wild
Unconfirmed
What it is

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS
0.00156 · 5.1th percentile
Weakness
CWE-99 · Improper Control of Resource Identifiers ('Resource Injection')
Published
2026-08-28T00:18Z
References (2)
EPSS history
Timeline
  • 27 AUG 18:32Z
    Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver
    cvelistv5