Improper Data Query Logic in MongoDB Ruby Driver
CVE-2026-88030

6.1MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
10 September 2026

What is CVE-2026-88030?

The MongoDB Ruby Driver contains a security flaw in its GridFS component due to improper handling of special elements in data query logic. This vulnerability allows an authenticated user to manipulate the structured file identifier passed by the application, leading to unintended query interpretations. As a result, the attacker may gain access to stored file content beyond the designated target or potentially delete all file chunks in the affected GridFS bucket. This can render stored file content unreadable, posing a significant security risk.

Affected Version(s)

Ruby Driver 2.0.0 <= 2.25.0

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.