CVE-2026-81490: MongoDB BI Connector
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting server message as transient and, after the configured retries are exhausted, proceeds without a valid result, ending the schema refresh routine. The mongosqld process continues running without a usable schema, so SQL clients are unable to obtain results until an operator removes the view or excludes its namespace from sampling.
Affected products
- MongoDB BI Connector: before 2.14.31 (fixed in 2.14.31)
Published 2026-08-28. Last modified 2026-09-29.