www.mongodb.com
High-Severity Vulnerabilities in MongoDB BI Connector Require Immediate Attention
Article Content
MongoDB disclosed multiple vulnerabilities affecting its BI Connector and database drivers, including six rated as high severity. Key issues include CVE-2026-81532, an improper-bounds-checking flaw in the ODBC driver, and CVE-2026-77586, which allows SQL injection via unescaped identifiers in SHOW CREATE output. Other vulnerabilities include CVE-2026-81520, permitting unauthenticated SASL-session exhaustion, and CVE-2026-81517, where logging errors could crash the mongosqld process. Organizations using MongoDB drivers and the BI Connector are urged to apply updates promptly, as some Debian packages remain unpatched. The BI Connector is set to reach end of life after September 2026, with the MongoDB SQL Interface recommended for new projects. No public exploits are known at this time, but the vulnerabilities pose significant risks if left unaddressed.
Key Points: • MongoDB disclosed 12 vulnerabilities, six rated high severity. • Immediate patching is required for affected BI Connector and database drivers. • The BI Connector will reach end of life after September 2026.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.