No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2026-12 |
|
Fri, 06 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sim
Sim sim |
|
| CPEs | cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sim
Sim sim |
Wed, 04 Mar 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Simstudioai
Simstudioai sim |
|
| Vendors & Products |
Simstudioai
Simstudioai sim |
Mon, 02 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data. | |
| Title | Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2026-03-02T13:33:23.987Z
Reserved: 2026-03-02T12:35:15.152Z
Link: CVE-2026-3431
Updated: 2026-03-02T13:33:20.459Z
Status : Analyzed
Published: 2026-03-02T13:16:05.197
Modified: 2026-03-06T20:30:24.963
Link: CVE-2026-3431
No data.
OpenCVE Enrichment
Updated: 2026-03-03T08:45:14Z