A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each such session retains a worker, a client connection slot, and its associated backend database connections until the process is restarted. Repeated use of this behavior can consume the configured connection capacity and prevent legitimate users from establishing new sessions.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 29 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb bi Connector |
|
| Vendors & Products |
Mongodb
Mongodb bi Connector |
Fri, 28 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each such session retains a worker, a client connection slot, and its associated backend database connections until the process is restarted. Repeated use of this behavior can consume the configured connection capacity and prevent legitimate users from establishing new sessions. | |
| Title | MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaustion | |
| Weaknesses | CWE-1088 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published: 2026-08-28T20:22:42.151Z
Updated: 2026-08-31T18:36:18.134Z
Reserved: 2026-08-26T22:10:21.151Z
Link: CVE-2026-81520
Updated: 2026-08-31T18:36:14.444Z
Status : Awaiting Analysis
Published: 2026-08-28T22:16:54.650
Modified: 2026-09-01T21:03:04.987
Link: CVE-2026-81520
No data.