{"apiVersion":"1.0","identifier":"CVE-2026-81521","description":"The MongoDB Go Driver-s client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.","publishedAt":"2026-08-27T20:18:50","lastModifiedAt":"2026-08-28T00:18:20","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81521","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","epssProbability":0.00203,"riskScore":0.66,"affectedProduct":"MongoDB Go Driver","affectedVersions":"unknown","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-81521","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-81521","en":"https://www.redsauce.net/en/cves/CVE-2026-81521","fr":"https://www.redsauce.net/fr/cves/CVE-2026-81521","pt":"https://www.redsauce.net/pt/cves/CVE-2026-81521","de":"https://www.redsauce.net/de/cves/CVE-2026-81521","sk":"https://www.redsauce.net/sk/cves/CVE-2026-81521","el":"https://www.redsauce.net/el/cves/CVE-2026-81521"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-81521"}}