Improper Neutralization Vulnerability in MongoDB Python Driver
CVE-2026-88029

6.1MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
10 September 2026

What is CVE-2026-88029?

The MongoDB Python Driver's GridFS component is susceptible to an improper neutralization flaw. This vulnerability occurs when a structured file identifier, supplied by an authenticated user, is improperly handled. Instead of being treated as a literal identifier, it can be misinterpreted as a query condition. This mismanagement enables potential data breaches, allowing unauthorized access to stored files or even the deletion of entire GridFS file chunks within the affected bucket. Additionally, a vulnerable rename operation could mistakenly alter a file that the user did not intend to change.

Affected Version(s)

Python Driver 1.6.0 < 4.18.1

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.