Loading market data...
← Back to CVE feed

CVE-2026-81524

MEDIUM CVSS 5.4 View on NVD ↗

Description

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Published: Aug 27, 2026 20:18 UTC Modified: Aug 28, 2026 00:18 UTC