---
id: CVE-2026-81518
title: >-
  When mongosqld is configured with a client certificate authority file, the
  listener requests a client certificate during the TLS handshake but does not
  require one, so a client that presents no certificate is still accepted
summary: >-
  When mongosqld is configured with a client certificate authority file, the
  listener requests a client certificate during the TLS handshake but does not
  require one, so a client that presents no certificate is still accepted. In
  deploymen…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-295
vendor: mongodb
product: bi_connector
affected:
  - bi_connector < 2.14.31
patched:
  - bi_connector 2.14.31
published: '2026-08-28'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:14:48.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81518'
references:
  - url: 'https://www.mongodb.com/docs/bi-connector/current/release-notes/'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00253
epssPercentile: 0.15172
ingestedAt: '2026-09-29T19:44:04.121Z'
---

## Overview

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identifying users, a remote party with network access to the listener can therefore establish a session and read the MongoDB data exposed through the connector.

## Affected

- `bi_connector < 2.14.31`

## Remediation

Upgrade past the affected range:

- `bi_connector 2.14.31`
