CVE-2026-81527
Last modified
CVE-2026-81527 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When application-supplied values are embedded in certain query constructs, special elements contained within those values are not properly escaped before the resulting query is transmitted to the database, so portions of the value may be interpreted by the database as query logic rather than as data. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When application-supplied values are embedded in certain query constructs, special elements contained within those values are not properly escaped before the resulting query is transmitted to the database, so portions of the value may be interpreted by the database as query logic rather than as data. A user able to supply values that an application incorporates into an affected query may thereby cause unintended data to be returned or query results to be altered.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MongoDB | C# Driver | >= 2.14.0, < 3.11.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-81527?
How severe is CVE-2026-81527?
How do I fix CVE-2026-81527?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81521The MongoDB Go Driver's client-level bulk write operation ma…6.5
- CVE-2026-81522A weakness in the MongoDB C++ Driver's handling of caller-su…8.1
- CVE-2026-81523A missing input-validation issue in MongoDB libmongocrypt's …4.4
- CVE-2026-81524A weakness in the MongoDB C Driver allows special elements i…5.4
- CVE-2026-81525The MongoDB client library for PHP does not sufficiently san…8.1
- CVE-2026-81526The MongoDB Rust Driver does not neutralize special characte…6.5
- CVE-2026-81528A MongoDB C# driver document-replacement code path omits the…5.4
- CVE-2026-81529Improper neutralization of delimiters in connection-URL cons…7.1
- CVE-2026-8153OS command injection in Dashboard Server interface in Univer…9.8
- CVE-2026-81530A weakness in the client-side encryption configuration surfa…5.6
- CVE-2026-81532A user able to submit SQL through an application using the M…8.8
- CVE-2026-81533An application using the MongoDB BI Connector ODBC Driver ma…7.1
Are you affected by CVE-2026-81527?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
