Medium severity6.5NVD Advisory· Published Aug 27, 2026
CVE-2026-81521
CVE-2026-81521
Description
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2>=2.0,<2.5+ 1 more
- (no CPE)range: >=2.0,<2.5
- (no CPE)range: <2.8.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.