MEDIUMCVSS 5.4Vulnerability

CVE-2026-81524

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.

Properties

severity
MEDIUM
epss_score
0.00261
cvss_severity
MEDIUM
cvss_score
5.4
retrieved_at
2026-09-29T22:27:20+00:00
last_source
FIRST EPSS
score
5.4
cve_id
CVE-2026-81524
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
signal_observed_at
2026-09-29T22:17:56+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
published_at
2026-08-27T20:18:50.773
last_modified
2026-09-29T19:17:16.197
epss_percentile
0.16031

Related Entities (4)

ENRICHED_BY (1)

→[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

→[Product]

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81524 (CVSS 5.4) — Ninja Signal Threat Intelligence | Ninja Signal