Junglewise Threat Intelligence

CVE-2026-81528: MongoDB C# Driver NoSQL injection in document replacement

CVE-2026-81528 · Severity: medium · CVSS 5.4 · Published 2026-08-27

Technologies: MongoDB C Driver. Vendors: MongoDB.

Executive brief

The MongoDB C# driver's document-replacement feature fails to validate input when applications use loosely-typed collections, allowing attackers to inject MongoDB update operators into replacement values. This enables unauthorized database modifications and data exposure under the application's own database credentials. Applications using strongly-typed document mappings are not affected.

Technical details

The vulnerability is a NoSQL injection in the C# driver's document-replacement code path. The root cause is that the UpdateRequest.EnsureUpdateIsValid() method skips shape validation for Replacement-type updates (line 53 in UpdateRequest.cs), allowing any BsonValue (including BsonArray or scalar types) to pass through without sanitization. When an application passes untrusted, loosely-typed input as a replacement value, the driver wraps it in BsonDocumentWrapper and forwards it to the server without neutralizing special MongoDB operators. The ReplacementElementNameValidator only checks top-level element names and returns NoOpElementNameValidator for child content, allowing array indices and pipeline-stage operators to bypass validation. The server then interprets an array 'u' field as an aggregation-pipeline update and executes the attacker-supplied operators (e.g., $set, $unset, $replaceWith) with the application's database credentials. Exploitation requires passing attacker-controlled data to ReplaceOne() or FindOneAndReplace() with loosely-typed collections. The vulnerability is fixed in version 3.11.1 (released 2026-08-27).

Affected products

  • MongoDB C# Driver prior to 3.11.1

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Fixed in version 3.11.1

References

Related threats