Vulnerability in MongoDB C# Driver Impacts Application Filtering
CVE-2026-88026

7.1HIGH

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88026?

The MongoDB C# Driver contains a security flaw related to improper handling of regular-expression metacharacters within its LINQ query translation component. This vulnerability allows an authenticated user to manipulate character sequences, which can inadvertently alter intended regular-expression predicates. As a result, the application may return excessive records beyond what was originally meant to be filtered. This presents a significant risk as it can lead to unintended data exposure, impacting the confidentiality of the application's sensitive information.

Affected Version(s)

C# Driver 2.14.0 <= 3.11.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.