CVE-2026-81526: Cross-database write redirection via unvalidated dotted database name in bulk write namespaces

Published Aug 27, 2026
·
Updated

The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. An actor able to influence that identifier in an application using the driver may cause write operations to be applied to an unintended target within the same deployment using the application's own credentials. This may result in unauthorized modification of data belonging to another logical boundary enforced by the application.

Affected Software

1 affected component
MongoDB MongoDB Rust Driver

Event History

Aug 27, 2026
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using the MongoDB Rust Driver are exposed when an actor can influence a target identifier used in bulk write namespaces. The impact is limited to unintended targets within the same MongoDB deployment that the application's credentials can write to.

2

What access does an attacker need to exploit it?

An attacker needs the ability to influence the target identifier supplied by the application. Exploitation does not require user interaction, but requests are made using the application's own MongoDB credentials.

3

What is the impact of successful exploitation?

Successful exploitation can redirect write operations to another logical boundary in the same deployment, resulting in unauthorized data modification. The available information does not indicate confidentiality disclosure or service availability impact.

4

What can be done while patching is pending?

Ensure untrusted actors cannot control bulk write namespace target identifiers, and validate or restrict those identifiers before they are passed to the driver. Restrict the application's database credentials so they cannot write to unintended databases or logical boundaries.

5

How can I determine whether my application is affected?

Review bulk write code paths for caller-supplied target identifiers that are embedded in namespaces, particularly where identifiers can contain special characters such as dots. The referenced MongoDB Rust Driver release is v3.8.2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203