Improper Data Query Handling in MongoDB PHP Library by MongoDB
CVE-2026-88023

6.1MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
10 September 2026

What is CVE-2026-88023?

A vulnerability exists within the MongoDB PHP Library that arises when the GridFS component fails to properly handle special elements in data query logic. This flaw allows an authenticated user to manipulate a structured file identifier, leading to potentially unauthorized access to stored file content or the accidental deletion of all GridFS file chunks within the affected bucket. Additionally, the rename operation could inadvertently affect the wrong file, raising concerns about data integrity and security.

Affected Version(s)

MongoDB PHP Library 1.1.0 <= 1.21.4

MongoDB PHP Library 2.0.0 <= 2.4.1

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.