Mongodb
Mongodb BI Connector: vulnerabilidades y CVE
Mongodb BI Connector tiene 8 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses8
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81520 | Alta (8.7) | 0.42% | — | 28 ago 2026 | A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because… |
| CVE-2026-81518 | Alta (8.7) | 0.25% | — | 28 ago 2026 | When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still… |
| CVE-2026-81517 | Alta (8.7) | 0.46% | — | 28 ago 2026 | An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log… |
| CVE-2026-81490 | Alta (8.3) | 0.42% | — | 28 ago 2026 | A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic… |
| CVE-2026-77586 | Alta (8.5) | 0.42% | — | 28 ago 2026 | In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier… |
| CVE-2026-77184 | Media (5.7) | 0.30% | — | 28 ago 2026 | In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment text of the DDL returned by SHOW CREATE statements without complete escaping of backslash… |
| CVE-2026-75573 | Media (4.1) | 0.10% | — | 27 ago 2026 | In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with… |
| CVE-2026-75159 | Alta (8.2) | 0.28% | — | 27 ago 2026 | An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.