Description
Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence such an identifier may delete all embedded documents in a targeted record or overwrite an embedded document other than the intended target.
Published: 2026-09-10
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Mass deletion or overwrite of embedded documents in Laravel's MongoDB integration leads to data loss and integrity compromise
Action: Apply Patch
AI Analysis

Impact

Improper neutralization of query operators in the embedded‑document relation handling allows a caller to supply an identifier that is interpreted as a filter condition. An authenticated user who can influence such an identifier can either delete every embedded document within a target record or overwrite a different embedded document, resulting in significant data loss or corruption. The weakness is classified as CWE‑943.

Affected Systems

MongoDB integration for Laravel (PHP). No specific product version information is provided; the vulnerability exists in any affected release of the MongoDB Laravel driver where the identifier is not properly checked.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate to high severity, and the EPSS score is not available, suggesting limited publicly available exploitation data. The vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated with write privileges to the target record; thus, the threat surface is confined to users with sufficient access. Once an attacker meets this prerequisite, they can directly manipulate the database through the application’s API without needing additional network or privilege escalation steps.

Generated by OpenCVE AI on September 11, 2026 at 00:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Laravel's MongoDB integration to the latest version that includes the injection fix.
  • Enforce strict role‑based access control so only trusted users can modify embedded documents.
  • Validate and sanitize embedded record identifiers before using them in queries, ensuring query operators cannot be injected.

Generated by OpenCVE AI on September 11, 2026 at 00:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb laravel Mongodb
CPEs cpe:2.3:a:mongodb:laravel_mongodb:*:*:*:*:*:*:*:*
Vendors & Products Mongodb laravel Mongodb

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb laravel Mongodb (php)
Vendors & Products Mongodb
Mongodb laravel Mongodb (php)

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence such an identifier may delete all embedded documents in a targeted record or overwrite an embedded document other than the intended target.
Title Mass deletion and overwrite of embedded documents via query-operator injection in embedded record keys in MongoDB integration for Laravel
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Laravel Mongodb Laravel Mongodb (php)
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-10T18:22:21.724Z

Reserved: 2026-09-09T19:49:39.183Z

Link: CVE-2026-88027

cve-icon Vulnrichment

Updated: 2026-09-10T18:22:14.390Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T18:18:13.030

Modified: 2026-09-29T16:15:26.277

Link: CVE-2026-88027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:59:59Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic