← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 27, 2026 · 20:18via CVEFeed

CVE-2026-81524 - Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver

Brief

CVE ID : CVE-2026-81524

Published : Aug. 27, 2026, 8:18 p. m.

  • 55 minutes ago

Description : A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.

Severity: 5.4

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed