Description
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Published: 2026-09-10
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Loss
Action: Assess Impact
AI Analysis

Impact

The MongoDB Go Driver contains a flaw in its GridFS component identifier that is interpreted as a query condition instead of a literal identifier. This improper neutralization allows the attacker to delete all GridFS file chunks within a bucket, effectively erasing stored data. The weakness is categorized as CWE-1287 and CWE-943, reflecting improper neutralization of special elements in query logic.

Affected Systems

The vulnerability affects applications that use the MongoDB Go Driver. No specific driver versions are listed in the known data, so impacted.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium severity risk. The EPSS score of < 1% shows a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated user with the ability to influence the file identifier passed to the driver. While the exact application context is not specified, it is inferred that the threat vector is through controlled input to an authenticated credentials or exploit another vulnerability to gain that capability.

Generated by OpenCVE AI on September 21, 2026 at 05:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MongoDB Go Driver to a version that fixes CVE- a patch is available
  • Validate or sanitize file identifiers on interpreted as query conditions
  • Restrict authenticated users to only those with legitimate file access rights and monitor for anomalous deletion requests

Generated by OpenCVE AI on September 21, 2026 at 05:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:go_driver:*:*:*:*:*:mongodb:*:*

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1287
References
Metrics threat_severity

None

threat_severity

Important


Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb go Driver
Vendors & Products Mongodb
Mongodb go Driver

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Title GridFS data deletion via query-operator injection in file IDs in the MongoDB Go Driver
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Go Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-10T18:25:57.644Z

Reserved: 2026-09-09T19:49:39.183Z

Link: CVE-2026-88031

cve-icon Vulnrichment

Updated: 2026-09-10T18:25:55.333Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T18:18:13.600

Modified: 2026-09-29T15:58:34.990

Link: CVE-2026-88031

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T17:59:35Z

Links: CVE-2026-88031 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:30:07Z

Weaknesses
  • CWE-1287

    Improper Validation of Specified Type of Input

  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic