SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81523

MEDIUM · CVSS 4.4 EPSS 0.07% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MongoDB's libmongocrypt is vulnerable due to a missing input validation in its automatic-encryption context setup, allowing unsanitized caller-supplied database identifiers. This flaw can result in incorrect schema selection, potentially leading to limited information disclosure or unauthorized modifications. Organizations using MongoDB should prioritize addressing this vulnerability to mitigate risks associated with data integrity and confidentiality.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81523
Severity
MEDIUM
CVSS
4.4
EPSS
0.07%
MongoDB

Original NVD Description

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema selection, which may lead to limited disclosure or modification of information handled by the application.

Related CVEs

Other vulnerabilities affecting the same vendor(s)