Description
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Published: 2026-09-10
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure and Deletion via Query-Operator Injection
Action: Immediate Patch
AI Analysis

Impact

Improper neutralization of special elements in GridFS query logic inside the MongoDB C++ Driver allows an authenticated caller to supply a structured file identifier that is interpreted as a query condition rather than a literal value. This flaw can lead to two significant impacts: an attacker can read content from files beyond the intended target, thereby disclosing sensitive data, or cause all GridFS file chunks in the affected bucket to be removed, resulting disabling subsequent read operations. Both outcomes compromise confidentiality and availability.

Affected Systems

This vulnerability affects applications that use the MongoDB C++ Driver to work with GridFS. No specific driver versions are listed in the advisory, so any installation of the driver that includes the vulnerable GridFS component remains at risk.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so the precise exploitation likelihood is uncertain. The likely attack vector is an authenticated user or application component that can influence the file identifier passed to the driver; from that position an attacker could inject query operators to read or delete data. Without patching or mitigating input handling, the potential for unauthorized data exposure or bucket data loss remains significant.

Generated by OpenCVE AI on September 10, 2026 at 23:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest patched release of the MongoDB C++ Driver that addresses the GridFS query-operator injection flaw.
  • Implement strict input validation on all file identifier values used in GridFS operations, ensuring they are treated strictly as literal identifiers and not parsed for query operators.
  • Apply least‑privilege access controls to the GridFS bucket and monitor for anomalous read or delete activity to detect potential abuse.

Generated by OpenCVE AI on September 10, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb c\+\+ Driver
CPEs cpe:2.3:a:mongodb:c\+\+_driver:*:*:*:*:*:mongodb:*:*
Vendors & Products Mongodb c\+\+ Driver

Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb c++ Driver
Vendors & Products Mongodb
Mongodb c++ Driver

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Title GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C++ Driver
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb C++ Driver C\+\+ Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-10T18:30:17.942Z

Reserved: 2026-09-09T19:49:52.213Z

Link: CVE-2026-88034

cve-icon Vulnrichment

Updated: 2026-09-10T18:30:12.722Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T19:17:40.817

Modified: 2026-09-16T18:00:36.920

Link: CVE-2026-88034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:15:15Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic