Description
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Published: 2026-09-10
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure and Denial of Service
Action: Apply Patch
AI Analysis

Impact

The MongoDB Ruby Driver’s GridFS component fails to neutralize special elements in a caller‑supplied structured file identifier, allowing the identifier to be interpreted as a query condition instead of a literal. This query‑operator injection, classified as CWE‑917 and CWE‑943, lets an authenticated user read file content beyond the intended target or delete all chunks of a GridFS bucket, resulting in data disclosure and denial of service.

Affected Systems

The vulnerability affects the MongoDB Ruby Driver. No specific version ranges are listed, so any installed version of the driver should be assumed at risk until an updated package that resolves the injection flaw is deployed.

Risk and Exploitability

With a CVSS score of 6.1, the risk is moderate. The EPSS score of 0.00259 indicates an extremely low but nonzero probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to control or influence a file identifier supplied to the driver, typically through an authenticated application component. No additional network exposure beyond normal driver usage is required for exploitation.

Generated by OpenCVE AI on September 21, 2026 at 05:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MongoDB Ruby Driver to the latest fixed version as soon as it becomes available.
  • Validate or sanitize all file identifiers before passing them to the driver so that only literal identifiers are accepted.
  • Restrict application components or users that can supply file identifiers to the minimum necessary privileges and monitor GridFS operation logs for unexpected reads or deletions.

Generated by OpenCVE AI on September 21, 2026 at 05:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:ruby_driver:*:-:*:*:*:mongodb:*:*

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-917
References
Metrics threat_severity

None

threat_severity

Important


Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb ruby Driver
Vendors & Products Mongodb
Mongodb ruby Driver

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Title GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Ruby Driver
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Ruby Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-10T18:25:23.632Z

Reserved: 2026-09-09T19:49:39.183Z

Link: CVE-2026-88030

cve-icon Vulnrichment

Updated: 2026-09-10T18:25:20.806Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T18:18:13.463

Modified: 2026-09-29T16:03:10.493

Link: CVE-2026-88030

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T17:57:59Z

Links: CVE-2026-88030 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:30:07Z

Weaknesses
  • CWE-917

    Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic