CVE-2026-81518(mongodb / bi_connector)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identifying users, a remote party with network access to the listener can therefore establish a session and read the MongoDB data exposed through the connector.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bi_connector

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
bi_connector

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-30: 109-30
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    #ALERT CVE-2026-81518 | CVSS 7.5 HIGH mongosqld TLS auth bypass: Client certs requested but not enforced, allowing unauthorized MongoDB data access when cert-based auth is sole protection. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/IGf32pz4m3

    0000027
    141 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbbi_connector---

Explore more