Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81517— MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of SQL Service

Quick assessment

Affected
MongoDB BI Connector
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

能够访问 MongoDB for BI 连接器(mongosqld)实例端口的未认证方,可能产生大量的常规连接日志活动,从而耗尽为配置的日志路径提供后端的存储空间。当后续的日志写入或日志轮换操作失败时,由此产生的错误未被处理,导致共享的 mongosqld 进程终止,进而终止所有已连接 SQL 客户端的服务。该进程在启动时仍会持续终止,直到运维人员恢复可用的存储空间,且解释该故障状况的诊断信息也未被记录。

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81517

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of SQL Service
Source: CVE Program / CVE List V5
Vulnerability Description
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operation subsequently fails, the resulting error is not handled and the shared mongosqld process ends, ending service for all connected SQL clients. The process continues to end on startup until an operator restores available storage, and the diagnostic message explaining the condition is not recorded.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未捕获的异常
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB BI Connector 0 ~ 2.14.31 -

II. Public POCs for CVE-2026-81517

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81517

登录查看更多情报信息。

Same Patch Batch · MongoDB · 2026-08-28 · 11 CVEs total

CVE-2026-81532 8.8 HIGH BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corrupt
CVE-2026-77586 8.0 HIGH MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output
CVE-2026-81490 7.7 HIGH MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of
CVE-2026-81518 7.5 HIGH BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections
CVE-2026-81520 7.5 HIGH MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaus
CVE-2026-81533 7.1 HIGH MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values
CVE-2026-76798 6.3 MEDIUM MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports
CVE-2026-76797 6.3 MEDIUM MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generate
CVE-2026-77184 5.2 MEDIUM MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE O
CVE-2026-76794 4.6 MEDIUM MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Da

IV. Related Vulnerabilities

V. Comments for CVE-2026-81517

No comments yet


Leave a comment