CVE-2026-3431

O

n SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data.

Configurations

No configuration.

History

02 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 13:16

Updated : 2026-03-02 20:29


NVD link : CVE-2026-3431

Mitre link : CVE-2026-3431

CVE.ORG link : CVE-2026-3431


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization