CVE Feed

    Dashboard / CVE / CVE-2026-81529

    CVE-2026-81529

    Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connection-URL builder and round-trips the builder back into a client configuration, the untrusted text is serialized without neutralizing the URL/option delimiters and is then re-parsed as authoritative connection options. A low-privileged user of such an application can thereby introduce or suppress security-relevant connection settings.

    Published:Aug 27, 2026
    Last Modified:Aug 28, 2026
    EPS:Aug 27, 2026
    EPSS Score:0.00174
    CVSS Score:7.1

    Affected Products

    Vendor
    Mongodb
    Product
    C# Driver

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High