← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 27, 2026 · 20:18via CVEFeed

CVE-2026-81522 - Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ Driver

Brief

CVE ID : CVE-2026-81522

Published : Aug. 27, 2026, 8:18 p. m.

  • 55 minutes ago

Description : A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may therefore have its operation directed at a different target than intended.

This can result in limited unauthorized read and write access to data belonging to another logical tenant of the affected application.

Severity: 8.6

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed