Threat Advisory

MongoDB Flaws Allow Cross-Tenant Database Retargeting and Credential Exposure

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting MongoDB C# Driver: Versions 2.10.0 through 3.11.0, Rust Driver: Versions 3.0.0 through 3.8.1, PHP Library/Extension: Versions prior to 1.21.4 (Library) and 1.21.6 (Extension). Also affects 2.0.0 through 2.4.0, C Driver: Versions 1.0.0 through 2.5.0, C++ Driver: Versions 3.0.0 through 4.5.0, Go Driver: Versions 2.1.0 through 2.8.1, BI Connector: Versions 2.4.0 (and 2.12.0) through 2.14.29.

CVE-2026-81525 (CVSS 8.6 — High): This vulnerability allows cross-tenant database retargeting via dot/NUL injection, enabling attackers to silently direct operations to unintended storage locations.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting MongoDB C# Driver: Versions 2.10.0 through 3.11.0, Rust Driver: Versions 3.0.0 through 3.8.1, PHP Library/Extension: Versions prior to 1.21.4 (Library) and 1.21.6 (Extension). Also affects 2.0.0 through 2.4.0, C Driver: Versions 1.0.0 through 2.5.0, C++ Driver: Versions 3.0.0 through 4.5.0, Go Driver: Versions 2.1.0 through 2.8.1, BI Connector: Versions 2.4.0 (and 2.12.0) through 2.14.29.

CVE-2026-81525 (CVSS 8.6 — High): This vulnerability allows cross-tenant database retargeting via dot/NUL injection, enabling attackers to silently direct operations to unintended storage locations.[emaillocker id="1283"]

CVE-2026-75159 (CVSS 8.2 — Medium): Unauthenticated attackers can terminate the mongosqld process, disrupting BI Connector availability by causing an improper memory handling condition.

CVE-2026-81524: This vulnerability involves cross-tenant database retargeting via dot/NUL injection in the C driver.

CVE-2026-81522: This vulnerability allows cross-tenant database retargeting via dot/NUL injection in the C++ driver.

CVE-2026-81526: Unauthorized cross-database write redirection is enabled in the Rust driver due to inadequate sanitization.

CVE-2026-81528: NoSQL injection is possible by bypassing update shape validation during document replacement in the C# driver.

CVE-2026-81529: Connection-option injection is allowed because the connection-URL builder fails to neutralize delimiters in the C# driver.

CVE-2026-81530: The KMS master key is exposed in plaintext diagnostic outputs in the C# driver.

CVE-2026-75573: TLS private-key passwords are logged in standard error when duplicate options exist for the BI Connector.

These vulnerabilities collectively present a massive risk to organizations using MongoDB.

RECOMMENDATION:

We recommend you refer below link: https://www.mongodb.com/resources/products/alerts

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu