CVE-2026-81517: MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of SQL Service

Published Aug 28, 2026
·
Updated

An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operation subsequently fails, the resulting error is not handled and the shared mongosqld process ends, ending service for all connected SQL clients. The process continues to end on startup until an operator restores available storage, and the diagnostic message explaining the condition is not recorded.

Affected Software

1 affected component
MongoDB MongoDB Connector for BI (mongosqld)

Event History

Aug 28, 2026
CVE Published
via MITRE·08:14 PM
Data Sourced
via MITRE·08:14 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

mongosqld instances whose port is reachable by unauthenticated parties are exposed if the storage backing the configured log path can be exhausted.

2

Does an attacker need credentials or user interaction?

No. An unauthenticated party only needs network reachability to the mongosqld port and can generate routine connection log activity.

3

What can be done if the service is already failing?

Restore available storage for the configured log path. The shared mongosqld process will continue to end on startup until storage is restored.

4

How can operators recognize this condition?

All connected SQL clients lose service when the shared mongosqld process ends, and repeated startup failures continue while storage remains unavailable. The diagnostic message explaining the condition is not recorded.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203