The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb go Driver |
|
| Vendors & Products |
Mongodb
Mongodb go Driver |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected. | |
| Title | Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver | |
| Weaknesses | CWE-99 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-27T20:41:59.025Z
Reserved: 2026-08-26T22:13:12.343Z
Link: CVE-2026-81521
No data.
Status : Received
Published: 2026-08-27T20:18:50.350
Modified: 2026-08-28T00:18:20.520
Link: CVE-2026-81521
No data.
OpenCVE Enrichment
Updated: 2026-08-28T07:30:07Z