CVE-2026-81526: MongoDB Rust Driver Vulnerability Exposes Data to Unauthorized Writes

CVE-2026-81526: MongoDB Rust Driver Vulnerability Exposes Data to Unauthorized Writes

First seen 28 Aug 2026, 23:49 UTC Feedlycvefeed.iosecurityonline.infojira.mongodb.orgvuldb.com 57.1

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-81526, has been identified in the MongoDB Rust Driver, which fails to neutralize special characters in caller-supplied target identifiers. This flaw allows an attacker to manipulate the identifier, potentially redirecting write operations to unintended targets within the same deployment. The vulnerability affects applications using the MongoDB Rust Driver, enabling unauthorized data modifications using the application's own credentials. The CVSS base score assigned to this vulnerability is 6.5, indicating a medium severity level. Organizations using affected versions of the driver are urged to patch immediately to prevent exploitation. As of now, there is no confirmed exploitation in the wild, but proof-of-concept exploits have been published. The vulnerability is categorized under CWE-74, relating to improper neutralization of special elements in output used by downstream components.

Key Points: • CVE-2026-81526 affects the MongoDB Rust Driver, allowing unauthorized data writes. • The vulnerability has a CVSS score of 6.5, indicating medium severity. • No active exploitation has been confirmed, but proof-of-concept exploits exist.

Timeline

2026-08-27
CVE-2026-81526 published
MongoDB Rust Driver vulnerability disclosed, allowing unauthorized data modifications.
cvefeed.io
2026-08-28
First details published by NVD
NVD assigns a CVSS base score of 6.5 to CVE-2026-81526, highlighting its potential impact.
Feedly