On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2026-12 |
|
History
Mon, 02 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data. | |
| Title | Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2026-03-02T13:33:23.987Z
Reserved: 2026-03-02T12:35:15.152Z
Link: CVE-2026-3431
Updated: 2026-03-02T13:33:20.459Z
Status : Received
Published: 2026-03-02T13:16:05.197
Modified: 2026-03-02T13:16:05.197
Link: CVE-2026-3431
No data.
OpenCVE Enrichment
No data.