CVE-2026-81490
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting server message as transient and, after the configured retries are exhausted, proceeds without a valid result, ending the schema refresh routine. The mongosqld process continues running without a usable schema, so SQL clients are unable to obtain results until an operator removes the view or excludes its namespace from sampling.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
- EPSS probability
- 0.24%
- CWE
- CWE-476
- Published
- 2026-08-28
- Last modified
- 2026-08-31
Affected products
- MongoDB BI Connector
Weakness type
Related vulnerabilities
- CVE-2026-78130 — strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute...
- CVE-2026-78126 — strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
- CVE-2026-45747 — Suricata lua/tls: null dereference in TlsGetCertInfo
- CVE-2026-86547 — mrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTER
- CVE-2026-66303 — Skype for Business and Lync Denial of Service Vulnerability
- CVE-2026-77901 — Microsoft Office Word Remote Code Execution Vulnerability
- CVE-2026-70575 — Windows Schannel Denial of Service Vulnerability
- CVE-2026-69881 — Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability