CVE-2026-81524

Source
https://cve.org/CVERecord?id=CVE-2026-81524
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81524.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-81524
Downstream
Published
2026-08-27T18:32:25.355Z
Modified
2026-08-29T11:30:50.770478413Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver
Details

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81524.json",
    "cwe_ids": [
        "CWE-99"
    ],
    "cna_assigner": "mongodb"
}
References

Affected packages

Git / github.com/mongodb/mongo-c-driver

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo-c-driver
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "fixed": "2.5.1"
        }
    ]
}

Affected versions

1.*
1.0.0
1.0.2
1.1.0
1.1.0-rc0
1.1.10
1.1.11
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.11.0
1.3.0
1.3.0-rc0
1.4.0-beta1
1.5.0-rc0
1.5.0-rc1
1.5.0-rc2
1.5.0-rc3
1.5.0-rc4
1.6.0
1.6.0-rc0
1.7.0-rc0
1.9.0-rc0
1.9.0-rc1
2.*
2.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81524.json"