Description
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Published: 2026-09-10
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data disclosure and deletion via GridFS query-operator injection
Action: Apply Patch
AI Analysis

Impact

An improper neutralization of special elements in the GridFS component of the MongoDB C Driver allows an attacker to supply a file identifier that is interpreted as a query condition instead of a literal value. An attacker who can influence the identifier may read files beyond the intended target or delete all GridFS file chunks in a bucket, effectively destroying stored data.

Affected Systems

The vulnerability affects applications that use the MongoDB C Driver, specifically the GridFS component, regardless of the vendor’s base product. No specific driver version information is provided.

Risk and Exploitability

The CVSS score is 6.1, indicating moderate severity, and the vulnerability is not listed in the CISA KEV catalog. Although the description does not explicity state the required access level, it is inferred that an authenticated user who can control the file identifier can exploit the flaw. Exploitation would involve crafting a malicious identifier to manipulate query logic, leading to data exposure or deletion.

Generated by OpenCVE AI on September 10, 2026 at 23:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest MongoDB C Driver version that addresses this vulnerability
  • Validate or sanitize all file identifiers before they are used in GridFS queries
  • Monitor logs for anomalous query conditions or repeated failures that could signal an injection attempt

Generated by OpenCVE AI on September 10, 2026 at 23:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*

Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb c Driver
Vendors & Products Mongodb
Mongodb c Driver

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Title GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C Driver
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb C Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-10T18:29:27.944Z

Reserved: 2026-09-09T19:49:55.477Z

Link: CVE-2026-88036

cve-icon Vulnrichment

Updated: 2026-09-10T18:29:24.423Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T19:17:41.100

Modified: 2026-09-16T18:13:54.583

Link: CVE-2026-88036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:15:15Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic