CVE-2026-81490: MongoDB BI Connector

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting server message as transient and, after the configured retries are exhausted, proceeds without a valid result, ending the schema refresh routine. The mongosqld process continues running without a usable schema, so SQL clients are unable to obtain results until an operator removes the view or excludes its namespace from sampling.

Affected products

  • MongoDB BI Connector: before 2.14.31 (fixed in 2.14.31)

Published 2026-08-28. Last modified 2026-09-29.