High-Severity Vulnerabilities in MongoDB BI Connector Require Immediate Attention

High-Severity Vulnerabilities in MongoDB BI Connector Require Immediate Attention

First seen 29 Aug 2026, 23:48 UTC mallory.aiwww.mongodb.com 65.2

Article Content

Browse articles
ThreatCluster

MongoDB disclosed multiple vulnerabilities affecting its BI Connector and database drivers, including six rated as high severity. Key issues include CVE-2026-81532, an improper-bounds-checking flaw in the ODBC driver, and CVE-2026-77586, which allows SQL injection via unescaped identifiers in SHOW CREATE output. Other vulnerabilities include CVE-2026-81520, permitting unauthenticated SASL-session exhaustion, and CVE-2026-81517, where logging errors could crash the mongosqld process. Organizations using MongoDB drivers and the BI Connector are urged to apply updates promptly, as some Debian packages remain unpatched. The BI Connector is set to reach end of life after September 2026, with the MongoDB SQL Interface recommended for new projects. No public exploits are known at this time, but the vulnerabilities pose significant risks if left unaddressed.

Key Points: • MongoDB disclosed 12 vulnerabilities, six rated high severity. • Immediate patching is required for affected BI Connector and database drivers. • The BI Connector will reach end of life after September 2026.

Timeline

2024-07-02
CVE-2024-24791 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-10-08
CVE-2025-11535 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-11-13
CVE-2025-47913 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-02
CVE-2025-61729 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-03
CVE-2025-61727 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-12
CVE-2026-19004 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-12
CVE-2026-19001 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-12
CVE-2026-18888 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-27
Multiple CVEs published
CVE-2026-81525, CVE-2026-81522, CVE-2026-81523, and CVE-2026-75159 were disclosed as high severity vulnerabilities.
mallory.ai
2026-08-27
CVE-2026-75573 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE