PatchSiren cyber security CVE debrief
CVE-2026-81517 MongoDB CVE debrief
A vulnerability in MongoDB Connector for BI (mongosqld) allows an unauthenticated party to exhaust storage by generating routine connection log activity. This leads to a denial of service for all connected SQL clients until available storage is restored. The vulnerability requires verification of storage capacity and monitoring of log paths, especially in environments with high connection activity. The impact is supported by the CVE record and NVD entry, but specific details on exploitation or victim impact are limited.
- Vendor
- MongoDB
- Product
- BI Connector
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-28
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-08-28
- Advisory updated
- 2026-09-29
Who should care
Defenders and operators of MongoDB Connector for BI (mongosqld) instances should assess exposure and prioritize verifying storage capacity and monitoring log paths. This includes reviewing current storage configurations, ensuring adequate logging and monitoring are in place, and planning for potential service disruptions. Security teams should also review incident response plans and conduct vulnerability scanning to identify exposed instances.
Why it matters
Defenders should care about CVE-2026-81517 because it allows an unauthenticated party to cause a denial of service in MongoDB Connector for BI (mongosqld) instances, potentially disrupting service and leading to data loss. The vulnerability requires verification of storage capacity and monitoring of log paths, especially in environments with high connection activity. The impact is supported by the CVE record and NVD entry, but specific details on exploitation or victim impact are not provided, limiting the understanding of the vulnerability's effects.
- Denial of service for all connected SQL clients
- Potential data loss or service disruption due to storage exhaustion
- Need for manual intervention to restore available storage
Technical summary
An unauthenticated party can exhaust storage by generating routine connection log activity in MongoDB Connector for BI (mongosqld), leading to a denial of service for all connected SQL clients. The process ends on startup until an operator restores available storage. This issue requires defenders to verify storage capacity and monitor log paths, especially in environments with high connection activity. The vulnerability is detailed in the CVE record and NVD entry, but specific exploitation details are not provided.
Defensive priority
Defenders should prioritize verifying storage capacity and monitoring log paths for MongoDB Connector for BI (mongosqld) instances, especially in environments with high connection activity.
Recommended defensive actions
- Verify storage capacity and configure log paths for MongoDB Connector for BI (mongosqld) instances
- Monitor connection activity and log paths for potential storage exhaustion
- Review and update MongoDB Connector for BI (mongosqld) versions to ensure running 2.14.31 or later
- Perform regular log reviews to detect potential storage issues
- Implement monitoring for storage capacity and alert on low storage conditions
- Conduct vulnerability scanning to identify exposed instances
- Review incident response plans for potential denial of service scenarios
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, specific details on exploitation or victim impact are not provided.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81517 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81517
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81517 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81517
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.mongodb.com/docs/bi-connector/current/release-notes/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.