Improper Data Query Handling in MongoDB Java Driver's GridFS Component
CVE-2026-88033

6.1MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
10 September 2026

What is CVE-2026-88033?

The MongoDB Java Driver's GridFS component has a vulnerability that allows an attacker to manipulate a structured file identifier in such a way that it's interpreted as a query condition. This results in potential unauthorized access to stored file content or the deletion of grid file chunks within the affected bucket. Furthermore, operations intended to rename files could inadvertently target the wrong files, compromising the integrity of stored data.

Affected Version(s)

Java Driver 3.3.0 < 5.11.1

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.