Improper Data Query Handling in MongoDB PHP Library by MongoDB
CVE-2026-88023
6.1MEDIUM
What is CVE-2026-88023?
A vulnerability exists within the MongoDB PHP Library that arises when the GridFS component fails to properly handle special elements in data query logic. This flaw allows an authenticated user to manipulate a structured file identifier, leading to potentially unauthorized access to stored file content or the accidental deletion of all GridFS file chunks within the affected bucket. Additionally, the rename operation could inadvertently affect the wrong file, raising concerns about data integrity and security.
Affected Version(s)
MongoDB PHP Library 1.1.0 <= 1.21.4
MongoDB PHP Library 2.0.0 <= 2.4.1