Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81518— BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections

Quick assessment

Affected
MongoDB BI Connector
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

当 配置了客户端证书颁发机构文件时,监听器会在 TLS 握手过程中请求客户端证书,但并不强制要求提供该证书,因此未出示证书的客户端仍会被接受。在依赖客户端证书作为识别用户唯一方式的环境中,能够访问监听器网络的远程方即可建立会话,并读取通过该连接器暴露的 MongoDB 数据。

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81518

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections
Source: CVE Program / CVE List V5
Vulnerability Description
When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identifying users, a remote party with network access to the listener can therefore establish a session and read the MongoDB data exposed through the connector.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB BI Connector 0 ~ 2.14.31 -

II. Public POCs for CVE-2026-81518

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81518

登录查看更多情报信息。

Same Patch Batch · MongoDB · 2026-08-28 · 11 CVEs total

CVE-2026-81532 8.8 HIGH BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corrupt
CVE-2026-77586 8.0 HIGH MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output
CVE-2026-81490 7.7 HIGH MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of
CVE-2026-81517 7.5 HIGH MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of S
CVE-2026-81520 7.5 HIGH MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaus
CVE-2026-81533 7.1 HIGH MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values
CVE-2026-76798 6.3 MEDIUM MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports
CVE-2026-76797 6.3 MEDIUM MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generate
CVE-2026-77184 5.2 MEDIUM MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE O
CVE-2026-76794 4.6 MEDIUM MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Da

IV. Related Vulnerabilities

V. Comments for CVE-2026-81518

No comments yet


Leave a comment