---
id: CVE-2026-81524
title: >-
  A weakness in the MongoDB C Driver allows special elements in caller-supplied
  database and collection name components to pass without sanitization when the
  driver composes the target namespace for an operation
summary: >-
  A weakness in the MongoDB C Driver allows special elements in caller-supplied
  database and collection name components to pass without sanitization when the
  driver composes the target namespace for an operation. An application that
  incorp…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-99
vendor: mongodb
product: c_driver
affected:
  - 'c_driver >= 1.0.0, < 2.5.1'
patched:
  - c_driver 2.5.1
published: '2026-08-27'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:17:16.197'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81524'
references:
  - url: 'https://github.com/mongodb/mongo-c-driver/releases/tag/2.5.1'
    label: cna@mongodb.com
  - url: 'https://jira.mongodb.org/browse/CDRIVER-6424'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00261
epssPercentile: 0.16031
ingestedAt: '2026-09-29T19:44:04.116Z'
---

## Overview

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.

## Affected

- `c_driver >= 1.0.0, < 2.5.1`

## Remediation

Upgrade past the affected range:

- `c_driver 2.5.1`
