CVE-2026-3431

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data.
References
Link Resource
https://www.tenable.com/security/research/tra-2026-12 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-02 13:16

Updated : 2026-06-17 10:43


NVD link : CVE-2026-3431

Mitre link : CVE-2026-3431

CVE.ORG link : CVE-2026-3431


JSON object : View

Products Affected

sim

  • sim
CWE
CWE-862

Missing Authorization