CVE-2026-81530 - Medium Severity Vulnerability
Vulnerable Library - mongodb.driver.3.8.0.nupkg
Official .NET driver for MongoDB.
Library home page: https://api.nuget.org/packages/mongodb.driver.3.8.0.nupkg
Sample Path to Dependency File: /src/SharpConnector.Api/SharpConnector.Api.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/mongodb.driver/3.8.0/mongodb.driver.3.8.0.nupkg,/home/wss-scanner/.nuget/packages/mongodb.driver/3.8.0/mongodb.driver.3.8.0.nupkg,/home/wss-scanner/.nuget/packages/mongodb.driver/3.8.0/mongodb.driver.3.8.0.nupkg
Dependency Hierarchy:
- ❌ mongodb.driver.3.8.0.nupkg (Vulnerable Library)
Found in base branch: main
Vulnerability Details
A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic representation of its client settings, instead of being masked as other secret fields are. A party able to read the application's logs, diagnostic output, or a process memory dump may thereby recover the plaintext credentials and use them to decrypt protected field data.
Publish Date: 2026-08-27
URL: CVE-2026-81530
CVSS 3 Score Details (5.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-27
Fix Resolution: MongoDB.Driver - 3.11.1,https://github.com/mongodb/mongo-csharp-driver.git - v3.11.1,mongodb.driver - 3.11.1
Step up your Open Source Security Game with Mend here
CVE-2026-81530 - Medium Severity Vulnerability
Official .NET driver for MongoDB.
Library home page: https://api.nuget.org/packages/mongodb.driver.3.8.0.nupkg
Sample Path to Dependency File: /src/SharpConnector.Api/SharpConnector.Api.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/mongodb.driver/3.8.0/mongodb.driver.3.8.0.nupkg,/home/wss-scanner/.nuget/packages/mongodb.driver/3.8.0/mongodb.driver.3.8.0.nupkg,/home/wss-scanner/.nuget/packages/mongodb.driver/3.8.0/mongodb.driver.3.8.0.nupkg
Dependency Hierarchy:
Found in base branch: main
A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic representation of its client settings, instead of being masked as other secret fields are. A party able to read the application's logs, diagnostic output, or a process memory dump may thereby recover the plaintext credentials and use them to decrypt protected field data.
Publish Date: 2026-08-27
URL: CVE-2026-81530
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-08-27
Fix Resolution: MongoDB.Driver - 3.11.1,https://github.com/mongodb/mongo-csharp-driver.git - v3.11.1,mongodb.driver - 3.11.1
Step up your Open Source Security Game with Mend here