Threat Advisory

MongoDB Flaw Allows Targeting Different Database or Collection

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-81525 is a high-severity vulnerability affecting mongodb/mongodb versions < 1.21.4 affecting mongodb/mongodb versions >= 2.0.0, < 2.4.1 with a CVSS score of 8.1, affecting MongoDB databases. The flaw type is CWE-943, an improper restriction of operations within the bounds of a memory buffer or written data. This vulnerability allows an attacker to target a different database or collection than specified by passing untrusted input as part of a database or collection name, potentially leading to unauthorized access and data tampering. The attack vector is network-based (AV:N), requiring low privileges (PR:L) with no user interaction (UI:N). Business impact includes significant disruption and potential financial loss for organizations relying on MongoDB databases.

RECOMMENDATION:

We recommend you to update mongodb to version 1.21.4 or 2.4.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-81525 is a high-severity vulnerability affecting mongodb/mongodb versions < 1.21.4 affecting mongodb/mongodb versions >= 2.0.0, < 2.4.1 with a CVSS score of 8.1, affecting MongoDB databases. The flaw type is CWE-943, an improper restriction of operations within the bounds of a memory buffer or written data. This vulnerability allows an attacker to target a different database or collection than specified by passing untrusted input as part of a database or collection name, potentially leading to unauthorized access and data tampering. The attack vector is network-based (AV:N), requiring low privileges (PR:L) with no user interaction (UI:N). Business impact includes significant disruption and potential financial loss for organizations relying on MongoDB databases.

RECOMMENDATION:

We recommend you to update mongodb to version 1.21.4 or 2.4.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu