Improper Data Query Handling in MongoDB Java Driver's GridFS Component
CVE-2026-88033
6.1MEDIUM
What is CVE-2026-88033?
The MongoDB Java Driver's GridFS component has a vulnerability that allows an attacker to manipulate a structured file identifier in such a way that it's interpreted as a query condition. This results in potential unauthorized access to stored file content or the deletion of grid file chunks within the affected bucket. Furthermore, operations intended to rename files could inadvertently target the wrong files, compromising the integrity of stored data.
Affected Version(s)
Java Driver 3.3.0 < 5.11.1