A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may therefore have its operation directed at a different target than intended. This can result in limited unauthorized read and write access to data belonging to another logical tenant of the affected application.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 28 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb c\# Driver |
|
| Vendors & Products |
Mongodb
Mongodb c\# Driver |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may therefore have its operation directed at a different target than intended. This can result in limited unauthorized read and write access to data belonging to another logical tenant of the affected application. | |
| Title | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ Driver | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-27T20:41:59.743Z
Reserved: 2026-08-26T22:13:42.143Z
Link: CVE-2026-81522
No data.
Status : Received
Published: 2026-08-27T20:18:50.493
Modified: 2026-08-28T00:18:20.623
Link: CVE-2026-81522
No data.
OpenCVE Enrichment
Updated: 2026-08-28T15:30:08Z
Weaknesses