{"id":"CVE-2026-81518","title":"When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted","summary":"When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deploymen…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-295"],"vendor":"mongodb","product":"bi_connector","affected":["bi_connector < 2.14.31"],"patched":["bi_connector 2.14.31"],"published":"2026-08-28","updated":"2026-09-29","sourceUpdated":"2026-09-29T19:14:48.440","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81518","references":[{"url":"https://www.mongodb.com/docs/bi-connector/current/release-notes/","label":"cna@mongodb.com"}],"tags":["nvd"],"epss":0.00253,"epssPercentile":0.15172,"ingestedAt":"2026-09-29T19:44:04.121Z","slug":"CVE-2026-81518","body":"## Overview\n\nWhen mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identifying users, a remote party with network access to the listener can therefore establish a session and read the MongoDB data exposed through the connector.\n\n## Affected\n\n- `bi_connector < 2.14.31`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `bi_connector 2.14.31`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}