CVE-2026-81524

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-27 20:18

Updated : 2026-08-28 21:16


NVD link : CVE-2026-81524

Mitre link : CVE-2026-81524

CVE.ORG link : CVE-2026-81524


JSON object : View

Products Affected

No product.

CWE
CWE-99

Improper Control of Resource Identifiers ('Resource Injection')