CVE-2026-81522
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
27/08/2026
Last modified:
29/08/2026
Description
A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may therefore have its operation directed at a different target than intended. This can result in limited unauthorized read and write access to data belonging to another logical tenant of the affected application.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.10
Severity 3.x
HIGH



