Description
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Published: 2026-09-10
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data disclosure and deletion via query injection
Action: Apply Update
AI Analysis

Impact

The MongoDB Rust Driver's GridFS component fails to properly neutralize query‑operator characters in file identifiers. When an authenticated caller supplies a structured identifier that contains operator syntax, the driver interprets it as part of a query instead of a literal value. This flaw allows the attacker to read any file stored in the GridFS bucket or, if they supply a deletion‑style query, to delete all chunks in the bucket, effectively destroying stored data. The weakness is an improper code injection vulnerability (CWE-94) coupled with improper data validation (CWE-943), leading to data disclosure and deletion.

Affected Systems

The vulnerability affects applications that use the MongoDB Rust Driver. No specific driver versions are listed in the current advisory, so the impact extends to all releases until a patched version MongoDB Rust Driver contains an improper neutralization of special elements in its GridFS component (CWE-94, CWE-943). When a caller supplies a structured file identifier that includes query‑operator characters, the driver interprets it as a query condition instead of a literal identifier. This behaviour allows an attacker who can provide or influence the identifier to read file content that exceeds the intended scope or, in a more destructive scenario, to delete every file chunk in the affected GridFS bucket, rendering the stored file content unreadable.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity. The EPSS score is not disclosed, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user who can influence the file identifier passed by the application. An attacker with such access could potentially retrieve unintended files or permanently delete the bucket contents. The risk is therefore considered moderate to high for systems that expose or do not enforce strict input validation or least‑privilege access.

Generated by OpenCVE AI on September 11, 2026 at 05:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MongoDB Rust Driver to the latest released version that includes the fix.
  • Validate and sanitize any file identifier before passing it to the driver, ensuring no query‑operator characters are interpreted as part of a query.
  • Enforce least‑privilege on the application components that construct or provide file identifiers operations.

Generated by OpenCVE AI on September 11, 2026 at 05:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb rust Driver
CPEs cpe:2.3:a:mongodb:rust_driver:*:*:*:*:*:mongodb:*:*
Vendors & Products Mongodb rust Driver

Fri, 11 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb rust-driver
Vendors & Products Mongodb
Mongodb rust-driver

Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
References
Metrics threat_severity

None

threat_severity

Important


Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Title GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Rust Driver
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Rust-driver Rust Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-10T18:22:40.427Z

Reserved: 2026-09-09T19:49:39.183Z

Link: CVE-2026-88024

cve-icon Vulnrichment

Updated: 2026-09-10T18:22:37.005Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T18:18:12.607

Modified: 2026-09-29T16:33:08.460

Link: CVE-2026-88024

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T17:43:29Z

Links: CVE-2026-88024 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:30:09Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')

  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic