Improper Handling of Embedded Document Identifiers in MongoDB for Laravel
CVE-2026-88027

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
10 September 2026

What is CVE-2026-88027?

The integration of MongoDB with Laravel presents a significant security flaw, stemming from improper handling of identifiers in embedded-document relations. This vulnerability allows an authenticated user, who can manipulate an embedded record identifier, to execute unintended query conditions. As a result, they might delete all embedded documents within a targeted record or overwrite a specific embedded document, leading to severe data integrity issues. Developers utilizing this integration must be vigilant and apply necessary patches to maintain data security.

Affected Version(s)

Laravel MongoDB (PHP) 4.0.0 < 5.11.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.