当 配置了客户端证书颁发机构文件时,监听器会在 TLS 握手过程中请求客户端证书,但并不强制要求提供该证书,因此未出示证书的客户端仍会被接受。在依赖客户端证书作为识别用户唯一方式的环境中,能够访问监听器网络的远程方即可建立会话,并读取通过该连接器暴露的 MongoDB 数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | BI Connector | 0 ~ 2.14.31 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81532 | 8.8 HIGH | BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corrupt |
| CVE-2026-77586 | 8.0 HIGH | MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output |
| CVE-2026-81490 | 7.7 HIGH | MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of |
| CVE-2026-81517 | 7.5 HIGH | MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of S |
| CVE-2026-81520 | 7.5 HIGH | MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaus |
| CVE-2026-81533 | 7.1 HIGH | MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values |
| CVE-2026-76798 | 6.3 MEDIUM | MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports |
| CVE-2026-76797 | 6.3 MEDIUM | MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generate |
| CVE-2026-77184 | 5.2 MEDIUM | MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE O |
| CVE-2026-76794 | 4.6 MEDIUM | MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Da |
No comments yet