{"id":"CVE-2026-81490","title":"A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails","summary":"A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the re…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"mongodb","product":"bi_connector","affected":["bi_connector < 2.14.31"],"patched":["bi_connector 2.14.31"],"published":"2026-08-28","updated":"2026-09-29","sourceUpdated":"2026-09-29T19:15:04.110","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81490","references":[{"url":"https://www.mongodb.com/docs/bi-connector/current/release-notes/","label":"cna@mongodb.com"}],"tags":["nvd"],"epss":0.00411,"epssPercentile":0.32805,"ingestedAt":"2026-09-29T19:44:04.121Z","slug":"CVE-2026-81490","body":"## Overview\n\nA database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting server message as transient and, after the configured retries are exhausted, proceeds without a valid result, ending the schema refresh routine. The mongosqld process continues running without a usable schema, so SQL clients are unable to obtain results until an operator removes the view or excludes its namespace from sampling.\n\n## Affected\n\n- `bi_connector < 2.14.31`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `bi_connector 2.14.31`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}