---
id: CVE-2026-81528
title: >-
  A MongoDB C# driver document-replacement code path omits the
  element-name/shape validation that the equivalent write paths apply, so a
  value supplied as a replacement is forwarded to the server without
  neutralization of query-language sp…
summary: >-
  A MongoDB C# driver document-replacement code path omits the
  element-name/shape validation that the equivalent write paths apply, so a
  value supplied as a replacement is forwarded to the server without
  neutralization of query-language sp…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-943
vendor: mongodb
product: c#_driver
affected:
  - 'c#_driver >= 2.10.0, < 3.11.1'
patched:
  - c#_driver 3.11.1
published: '2026-08-27'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:16:27.513'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81528'
references:
  - url: 'https://jira.mongodb.org/browse/CSHARP-6158'
    label: cna@mongodb.com
  - url: 'https://www.nuget.org/packages/MongoDB.Driver/3.11.1'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00273
epssPercentile: 0.17735
ingestedAt: '2026-09-29T19:44:04.117Z'
---

## Overview

A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is forwarded to the server without neutralization of query-language special elements. An application that passes untrusted, loosely-typed input as a replacement value therefore allows that input to be interpreted by the database as update logic rather than as data, executing under the application's own database credentials. Applications using strongly-typed document mappings are not affected.

## Affected

- `c#_driver >= 2.10.0, < 3.11.1`

## Remediation

Upgrade past the affected range:

- `c#_driver 3.11.1`
