---
id: CVE-2026-81517
title: >-
  An unauthenticated party able to reach the port of a MongoDB Connector for BI
  (mongosqld) instance may generate enough routine connection log activity to
  exhaust the storage backing the configured log path
summary: >-
  An unauthenticated party able to reach the port of a MongoDB Connector for BI
  (mongosqld) instance may generate enough routine connection log activity to
  exhaust the storage backing the configured log path. When a log write or log
  rotati…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-248
vendor: mongodb
product: bi_connector
affected:
  - bi_connector < 2.14.31
patched:
  - bi_connector 2.14.31
published: '2026-08-28'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:14:57.157'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81517'
references:
  - url: 'https://www.mongodb.com/docs/bi-connector/current/release-notes/'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.0046
epssPercentile: 0.3743
ingestedAt: '2026-09-29T19:44:04.121Z'
---

## Overview

An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operation subsequently fails, the resulting error is not handled and the shared mongosqld process ends, ending service for all connected SQL clients. The process continues to end on startup until an operator restores available storage, and the diagnostic message explaining the condition is not recorded.

## Affected

- `bi_connector < 2.14.31`

## Remediation

Upgrade past the affected range:

- `bi_connector 2.14.31`
