On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2026-12 |
|
History
Wed, 04 Mar 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Simstudioai
Simstudioai sim |
|
| Vendors & Products |
Simstudioai
Simstudioai sim |
Mon, 02 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data. | |
| Title | Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published: 2026-03-02T13:00:58.829Z
Updated: 2026-03-02T13:33:23.987Z
Reserved: 2026-03-02T12:35:15.152Z
Link: CVE-2026-3431
Updated: 2026-03-02T13:33:20.459Z
Status : Awaiting Analysis
Published: 2026-03-02T13:16:05.197
Modified: 2026-03-02T20:29:29.330
Link: CVE-2026-3431
No data.