CVE-2026-81518: BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections

Published Aug 28, 2026
·
Updated

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identifying users, a remote party with network access to the listener can therefore establish a session and read the MongoDB data exposed through the connector.

Affected Software

1 affected component
MongoDB mongosqld

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    When configuring mongosqld with a client certificate authority file, ensure the listener requires a client certificate during the TLS handshake so that clients presenting no certificate are rejected.

    MongoDB BI Connector (mongosqld listener TLS) Client certificate requirement (TLS mutual authentication) = Require client certificates

Event History

Aug 28, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments should be prioritized for investigation?

Prioritize mongosqld listeners configured with a client certificate authority file where client certificates are the only mechanism used to identify users. The issue is reachable by remote parties that have network access to the listener.

2

Does an attacker need valid client credentials to connect?

No. Although the listener requests a client certificate during the TLS handshake, it accepts clients that present no certificate.

3

What could an unauthenticated connection expose?

A remote party may establish a session and read MongoDB data exposed through the BI Connector. The described impact is confidentiality loss; integrity and availability impacts are not identified.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203