CVE-2026-81526
Last modified
CVE-2026-81526 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. An actor able to influence that identifier in an application using the driver may cause write operations to be applied to an unintended target within the same deployment using the application's own credentials. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. An actor able to influence that identifier in an application using the driver may cause write operations to be applied to an unintended target within the same deployment using the application's own credentials. This may result in unauthorized modification of data belonging to another logical boundary enforced by the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MongoDB | Rust Driver | >= 3.0.0, < 3.8.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-81526?
How severe is CVE-2026-81526?
How do I fix CVE-2026-81526?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81520A network-reachable client that has not yet authenticated ca…7.5
- CVE-2026-81521The MongoDB Go Driver's client-level bulk write operation ma…6.5
- CVE-2026-81522A weakness in the MongoDB C++ Driver's handling of caller-su…8.1
- CVE-2026-81523A missing input-validation issue in MongoDB libmongocrypt's …4.4
- CVE-2026-81524A weakness in the MongoDB C Driver allows special elements i…5.4
- CVE-2026-81525The MongoDB client library for PHP does not sufficiently san…8.1
- CVE-2026-81527A NoSQL/expression injection weakness exists in the LINQ-to-…6.5
- CVE-2026-81528A MongoDB C# driver document-replacement code path omits the…5.4
- CVE-2026-81529Improper neutralization of delimiters in connection-URL cons…7.1
- CVE-2026-8153OS command injection in Dashboard Server interface in Univer…9.8
- CVE-2026-81530A weakness in the client-side encryption configuration surfa…5.6
- CVE-2026-81532A user able to submit SQL through an application using the M…8.8
Are you affected by CVE-2026-81526?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
