Improper Input Handling in MongoDB Rust Driver's GridFS Component
CVE-2026-88024

6.1MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
10 September 2026

What is CVE-2026-88024?

A vulnerability exists in the GridFS component of the MongoDB Rust Driver that allows an authenticated user to manipulate a caller-supplied structured file identifier. This manipulation can lead to the identifier being interpreted as a query condition rather than as a literal identifier. Consequently, an attacker may access stored file content beyond the intended target or trigger the removal of all GridFS file chunks within the affected bucket, rendering the stored file content unusable.

Affected Version(s)

Rust Driver 2.4.0 < 3.9.1

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.