Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 29 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb bi Connector |
|
| Vendors & Products |
Mongodb
Mongodb bi Connector |
Fri, 28 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identifying users, a remote party with network access to the listener can therefore establish a session and read the MongoDB data exposed through the connector. | |
| Title | BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-28T20:18:14.870Z
Reserved: 2026-08-26T22:07:10.996Z
Link: CVE-2026-81518
No data.
Status : Received
Published: 2026-08-28T22:16:54.510
Modified: 2026-08-28T22:16:54.510
Link: CVE-2026-81518
No data.
OpenCVE Enrichment
Updated: 2026-08-29T00:30:17Z
-
CWE-295
Improper Certificate Validation