A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 28 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb c Driver |
|
| Vendors & Products |
Mongodb
Mongodb c Driver |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended. | |
| Title | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver | |
| Weaknesses | CWE-99 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-27T20:42:01.035Z
Reserved: 2026-08-26T22:13:58.379Z
Link: CVE-2026-81524
No data.
Status : Received
Published: 2026-08-27T20:18:50.773
Modified: 2026-08-28T00:18:20.853
Link: CVE-2026-81524
No data.
OpenCVE Enrichment
Updated: 2026-08-28T07:30:07Z
Weaknesses