PT-2026-82737 · Mongodb · Libmongocrypt
CVE-2026-81523
·
Published
2026-08-27
·
Updated
2026-08-27
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MongoDB libmongocrypt (affected versions not specified)
Description
A missing input-validation issue exists in the automatic-encryption context setup of MongoDB libmongocrypt. This flaw allows a caller-supplied database identifier to be accepted without proper sanitization, enabling cross-tenant database retargeting via dot or NUL injection in namespace strings. This can result in incorrect schema selection, potentially leading to the limited disclosure or modification of information handled by the application.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libmongocrypt