High-Severity MongoDB Connector Vulnerability CVE-2026-81517 Disclosed

High-Severity MongoDB Connector Vulnerability CVE-2026-81517 Disclosed

First seen 29 Aug 2026, 23:48 UTC Feedlywww.incibe.esvulners.com 64.5

Article Content

Browse articles
ThreatCluster

CVE-2026-81517 details a vulnerability in the MongoDB Connector for BI that allows unauthenticated attackers to exhaust storage on the log path by generating excessive connection log activity. This can lead to the mongosqld process crashing, terminating service for all connected SQL clients, and preventing service restart until storage is restored. The CVSS base score is reported as 7.5 (CVSS 3.1) and 8.7 (CVSS 4.0), indicating high severity. There is currently no evidence of public proof-of-concept or exploitation in the wild. Recommendations include implementing network access controls, monitoring storage capacity, and configuring log rotation policies. The vulnerability was published on 2026-08-28, and security advisories have been released urging immediate patching.

Key Points: • CVE-2026-81517 affects MongoDB Connector for BI, allowing service disruption. • Unauthenticated attackers can exploit this vulnerability over the network. • Immediate action is recommended to prevent potential service outages.

Timeline

2026-08-28
CVE-2026-81517 published
MongoDB disclosed a vulnerability in the Connector for BI affecting service availability due to log handling issues.
Feedly
2026-08-29
Security advisories released
Advisories from multiple sources urge immediate patching and implementation of security measures.
www.incibe.es