MongoDB PHP Client Library Namespace Manipulation in Vendor Implementation
CVE-2026-81525
8.6HIGH
What is CVE-2026-81525?
The MongoDB PHP Client Library is susceptible to namespace manipulation, where insufficient sanitization of user-supplied namespace identifiers may lead to unintended database operations. Applications that incorporate untrusted text can potentially redirect operations to different storage locations, posing a significant risk to data integrity and security. Proper validation and sanitization measures should be implemented to mitigate this vulnerability.
Affected Version(s)
PHP Driver 1.0.0 < 2.4.1