当配置了 Kerberos 认证的 MongoDB BI 连接器部署中,能够访问该部署的未认证客户端,在精心构造的认证交互遇到特定的 GSSAPI 错误处理条件时,可能导致 进程终止。这将导致 BI 连接器的可用性中断,直到该进程重启。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | BI Connector | 2.4.0< 2.14.30 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | BI Connector | 2.4.0 ~ 2.14.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81522 | 8.1 HIGH | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ Dr |
| CVE-2026-81525 | 8.1 HIGH | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP Dr |
| CVE-2026-81529 | 7.1 HIGH | Connection-option injection via unescaped settings in the canonical MongoDB URL builder |
| CVE-2026-81521 | 6.5 MEDIUM | Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite |
| CVE-2026-81527 | 6.5 MEDIUM | NoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translation |
| CVE-2026-81526 | 6.5 MEDIUM | Cross-database write redirection via unvalidated dotted database name in bulk write namesp |
| CVE-2026-81530 | 5.6 MEDIUM | KMS master key exposure via unredacted credential serialization in driver settings string |
| CVE-2026-81528 | 5.4 MEDIUM | NoSQL injection via array replacement bypassing update shape validation in driver write pa |
| CVE-2026-81524 | 5.4 MEDIUM | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driv |
| CVE-2026-75573 | 4.4 MEDIUM | MongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Ar |
| CVE-2026-81523 | 4.4 MEDIUM | Cross-tenant database retargeting via dot/NUL injection in namespace strings in libmongocr |
No comments yet