CVE-2026-6691Disclosure(mongodb / c_driver)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mongodb c_driver systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • c_driver

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-06); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
c_driver

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-06: 3Mentions · 2026-05-13: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-06: 205-0605-13
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-063
Disclosure2Patch1
2026-05-131
General1
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CVE-2026-6691: mongo-c-driver Vulnerability A newly disclosed flaw in MongoDB’s C driver may impact apps using MongoDB connectivity. Security fixes are already rolling out across Linux distributions. Patch affected packages ASAP. #MongoDB #CVE #CyberSecurity

    Post summary

    A new flaw in MongoDB’s C driver, CVE‑2026‑6691, has been disclosed and vendor patches are already being disseminated to Linux distributions.

    0001068
    149 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6691 The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication… https://www.cve.org/CVERecord?id=CVE-2026-6691

    Post summary

    The entry announces a heap buffer overflow in MongoDB C Driver’s Cyrus SASL integration, highlighting the vulnerability type and linking to the official CVE record.

    00010176
    57.4K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos MongoDB ❗ CVE-2026-8063 ❗ CVE-2026-6691 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-mongodb-2/ https://t.co/fBMnvP3jCv

    Post summary

    The tweet lists two MongoDB CVEs and provides links for more information but offers no technical or exploit details.

    0000099
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6691 The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication… https://www.cve.org/CVERecord?id=CVE-2026-6691 ----- Traducción: CVE-2026-6691 La … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-6691, describing a heap buffer overflow in the MongoDB C Driver’s Cyrus SASL integration, but makes no mention of PoCs, exploits, active use, or patches.

    0000045
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbc_driver-mongodb-

Explore more