Skip to content
MongoDBCVE-2026-81520

A network-reachable client

High8.7CVE-2026-81520 · Published Aug 28, 2026 · updated Sep 1, 2026

A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each such session retains a worker, a client connection slot, and its associated backend database connections until the process is restarted. Repeated use of this behavior can consume the configured connection capacity and prevent legitimate users from establishing new sessions.

MongoDB advisory

Affected versions

PackageAffectedFixed in
BI Connector
Product
< 2.14.312.14.31
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1088

More MongoDB advisories

All MongoDB
Advisory
MongoDB BI Connector: null pointer dereference
High8.3Aug 28
An unauthenticated party able to reach the port of a MongoDB Connector for BI
High8.7Aug 28
MongoDB BI Connector: improper certificate validation
High8.7Aug 28
MongoDB BI Connector ODBC Driver: stack buffer overflow
High8.7Aug 28
MongoDB BI Connector ODBC Driver: stack buffer overflow
Medium6.0Aug 28
MongoDB BI Connector: SQL injection
High8.5Aug 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.