MEDIUMCVSS 6.5Vulnerability

CVE-2026-81526

The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. An actor able to influence that identifier in an application using the driver may cause write operations to be applied to an unintended target within the same deployment using the application's own credentials. This may result in unauthorized modification of data belonging to another logical boundary enforced by the application.

Properties

severity
MEDIUM
epss_score
0.00349
cvss_severity
MEDIUM
cvss_score
6.5
retrieved_at
2026-09-29T22:27:20+00:00
last_source
FIRST EPSS
score
6.5
cve_id
CVE-2026-81526
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
signal_observed_at
2026-09-29T22:17:56+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
published_at
2026-08-27T20:18:51.057
last_modified
2026-09-29T19:16:45.363
epss_percentile
0.25942

Related Entities (4)

ENRICHED_BY (1)

→[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

→[Product]

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81526 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal