MongoDB disclosed 12 vulnerabilities across its database drivers, cryptography library, and BI Connector, including six rated High severity. The most severe reported issues include CVE-2026-81525 (CVSS 8.6), in which namespace injection in the PHP driver can enable cross-tenant database retargeting; CVE-2026-81522, involving cross-database write redirection in the C++ driver; and CVE-2026-81521, involving injection risks in the Go driver. Debian packages for the PHP, Go, C++ and libmongocrypt components remain flagged as unpatched on affected releases, although no public exploits were known at publication.
The BI Connector fixes address SQL injection in SHOW CREATE output (CVE-2026-77586), unauthenticated SASL-session exhaustion (CVE-2026-81520), and an ODBC cursor-name buffer overflow that could crash an application or potentially enable code execution (CVE-2026-81532). MongoDB's August BI Connector release remediates several of these issues, while ODBC Driver version 1.4.10 adds cursor-name bounds checks. Organizations should inventory MongoDB drivers and BI Connector deployments, promptly apply vendor updates, enforce strict validation of untrusted database object names and connection parameters, and impose authentication-session timeouts and resource limits. MongoDB has also announced that the BI Connector will reach end of life after September 2026, with the MongoDB SQL Interface recommended for new projects.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-81532 was published as a high-severity improper-bounds-checking vulnerability in the BI Connector ODBC driver. Oversized positioned-cursor names can overflow a diagnostic buffer, potentially crashing the host application or enabling code execution in its context.
MongoDB released BI Connector ODBC Driver 1.4.10, adding a get_limit bounds check for CVE-2026-81533 and truncating cursor names to remediate CVE-2026-81532.
CVE-2026-81520 was published as a high-severity MongoDB Connector for BI flaw allowing unauthenticated clients to leave SASL authentication exchanges incomplete and consume workers, connection slots, and backend database connections.
MongoDB Connector for BI's CVE-2026-77586 was published as a high-severity flaw in which unescaped collection, field, or index names can inject SQL into generated SHOW CREATE output that is later replayed.
CVE-2026-81521, CVE-2026-81522, CVE-2026-81523, and CVE-2026-81525 were published and were listed as unpatched for affected Debian MongoDB driver or libmongocrypt packages. The notices reported no known exploits for these issues.
MongoDB released BI Connector fixes for TLS configuration (CVE-2026-81518), unescaped SHOW CREATE identifiers (CVE-2026-77586 and CVE-2026-77184), unbounded SASL negotiation (CVE-2026-81520), sampler retries (CVE-2026-81490), and a mongosqld logging-error crash (CVE-2026-81517).
MongoDB released BI Connector ODBC Driver 1.4.9, adding validation or clamping for floating-point conversion, catalog-name lengths, client integration parameters, DSN paths, and buffers to address CVE-2026-18888 and CVE-2026-19001 through CVE-2026-19004.
MongoDB fixed a crash triggered by failed Kerberos authentication (CVE-2026-75159) and stopped mongodrdl from logging passwords in output (CVE-2026-75573).
MongoDB released a BI Connector build with Go 1.25.9 and support for MongoDB 8.3.
MongoDB released a BI Connector build using Go 1.24.11 to address CVE-2025-61727 and CVE-2025-61729, and upgraded golang.org/x/crypto to 0.45.0 for CVE-2025-47913.
MongoDB fixed CVE-2025-11535, a local privilege-escalation issue caused by incorrect permissions on custom Windows installer paths.
MongoDB released a BI Connector version built with Go 1.23 to address GO-2025-3563.
MongoDB released a BI Connector build using Go 1.21.12 or later across supported operating systems to address CVE-2024-24791.
The BI Connector release upgraded golang.org/x/crypto from version 0.8.0 to 0.17.0. MongoDB also integrated Silk vulnerability scanning and began producing a public third-party dependency report.
MongoDB released a BI Connector update that hid .pem key-file passwords in logs.
MongoDB stated that the BI Connector for Atlas and on-premises deployments will reach end of life after September 2026 and recommended the MongoDB SQL Interface for new projects.
A report identified 12 MongoDB vulnerabilities, including six rated High severity, across database drivers and the BI Connector. It described namespace injection, NoSQL and connection-option injection, cross-database write redirection, sensitive-key disclosure, and denial-of-service risks, while stating that no active exploitation or public proof-of-concept was confirmed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcecvefeed.io
Open sourcemongodb.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.