Description
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target.
Published: 2026-09-10
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure and Deletion
Action: Immediate Patch
AI Analysis

Impact

An authentication-aware injection flaw in the GridFS component of the MongoDB C# Driver allows an attacker who can influence a structured file identifier to cause the driver to treat that identifier as a query expression instead of a literal file name. The result is that the attacker can read the contents of files that were not intended to be exposed, delete all data chunks in a bucket, or rename a file that is unrelated to the target. This breach of confidentiality is coupled with a potential loss of integrity and availability of the stored data.

Affected Systems

The issue affects applications that use the MongoDB C# Driver, specifically those that interact with GridFS. The driver is part of the MongoDB official .NET driver package. No specific driver version is listed in the data, so any deployments using the driver should review their version and verify if it contains the fix.

Risk and Exploitability

The vulnerability has a CVSS score of 6.1, indicating a moderate severity. No EPSS score is currently available. The flaw is not listed in CISA’s KEV catalog, indicating there have been no known large‑scale exploitation incidents reported so far. Given that the flaw requires the attacker to influence an authenticated file identifier, the attack vector is likely an application‑level user or a higher‑privilege system component, rather than a remote network exploit. The impact could be significant for applications that rely on GridFS for storing sensitive or critical data.

Generated by OpenCVE AI on September 10, 2026 at 23:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest released version of the MongoDB C# Driver that contains the GridFS query‑operator injection fix
  • If an update is not immediately possible, sanitize all file identifiers so that they are treated as literal values and not parsed as query expressions
  • Ensure that only trusted users or restricted roles can invoke code paths that manipulate GridFS file identifiers, delete or rename operations

Generated by OpenCVE AI on September 10, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb c\# Driver
CPEs cpe:2.3:a:mongodb:c\#_driver:*:*:*:*:*:mongodb:*:*
Vendors & Products Mongodb c\# Driver

Fri, 11 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb c# Driver
Vendors & Products Mongodb
Mongodb c# Driver

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target.
Title GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# Driver
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb C# Driver C\# Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-10T18:23:05.533Z

Reserved: 2026-09-09T19:49:39.183Z

Link: CVE-2026-88025

cve-icon Vulnrichment

Updated: 2026-09-10T18:23:01.856Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T18:18:12.747

Modified: 2026-09-29T16:19:20.727

Link: CVE-2026-88025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:15:17Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic