Skip to content
CVE-2026-81517 - Exploits & Severity

CVE-2026-81517 - Exploits & Severity

Feedly • August 29, 2026

An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operation subsequently fails, the resulting error is not handled and the shared mongosqld process ends, ending service for all connected SQL clients. The process continues to end on startup until an operator restores available storage, and the diagnostic message explaining the condition is not recorded.

An unauthenticated attacker over the network can exhaust storage on the log path by generating routine connection log activity, causing the mongosqld process to crash when log operations fail, which terminates service for all connected SQL clients and prevents service restart until storage is restored.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Information not provided

Implement network access controls to restrict connectivity to the mongosqld port to authorized clients only. Monitor and manage storage capacity on the log path to prevent exhaustion. Configure log rotation policies to manage log file sizes. Consider implementing rate limiting on connection attempts.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

NVD published the first details for CVE-2026-81517

A CVSS base score of 7.5 has been assigned.

Feedly found the first article mentioning CVE-2026-81517 . See article

GitHub Advisories released a security advisory .

High-Severity MongoDB Driver and BI Connector Flaws Require Immediate Patching

MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of SQL Service (CVE-2026-81517)

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)