CVE-2026-81522: MongoDB C++ Driver

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may therefore have its operation directed at a different target than intended. This can result in limited unauthorized read and write access to data belonging to another logical tenant of the affected application.

Affected products

  • MongoDB C++ Driver: from 3.0.0, before 4.5.2 (fixed in 4.5.2)

Published 2026-08-27. Last modified 2026-09-29.