Junglewise Threat Intelligence

CVE-2026-81518: MongoDB Connector for BI client certificate validation bypass

CVE-2026-81518 · Severity: high · CVSS 7.5 · Published 2026-08-28

Technologies: MongoDB Connector for BI. Vendors: MongoDB.

Executive brief

MongoDB Connector for BI (mongosqld) is a gateway that exposes MongoDB databases via SQL queries. When configured with client certificate authentication, the service incorrectly accepts connections without a valid certificate, bypassing the intended access control. An attacker with network access can connect and read all MongoDB data exposed through the connector without proper authentication.

Technical details

The vulnerability is an authentication bypass in the TLS handshake logic of mongosqld. When a client certificate authority file is configured, the listener requests a client certificate during the TLS handshake but fails to enforce its presence, allowing connections with no certificate to succeed. The root cause is improper validation of client certificate requirements during the TLS handshake. The attack vector is network-based with no authentication required—an unauthenticated attacker on the network can connect and read exposed MongoDB data. A patch addressing this validation enforcement is available in the MongoDB BI Connector release notes.

Affected products

  • MongoDB Connector for BI <UNKNOWN>

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: advisory: CVE-2026-81518 assigned

References

Related threats