Vulnerability Description
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting server message as transient and, after the configured retries are exhausted, proceeds without a valid result, ending the schema refresh routine. The mongosqld process continues running without a usable schema, so SQL clients are unable to obtain results until an operator removes the view or excludes its namespace from sampling.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-81490?
CVE-2026-81490 is a vulnerability with a CVSS score of 7.7 (HIGH). A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails....
How severe is CVE-2026-81490?
CVE-2026-81490 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-81490?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.