Threat Advisory

MongoDB Driver Flaws Allow Data Access Redirection

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting MongoDB driver components and client utilities across its database ecosystem have been identified. These flaws allow remote attackers to redirect database connections, trigger heap memory corruption, or execute unauthorized code. System administrators must upgrade their client drivers and tools immediately to maintain secure database operations.

CVE-2026-96749 (CVSS 8.4 — High): A signed integer overflow during BSON encoding in the Python native extension allows an application to write outside allocated buffer boundaries when encoding unusually large data.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting MongoDB driver components and client utilities across its database ecosystem have been identified. These flaws allow remote attackers to redirect database connections, trigger heap memory corruption, or execute unauthorized code. System administrators must upgrade their client drivers and tools immediately to maintain secure database operations.

CVE-2026-96749 (CVSS 8.4 — High): A signed integer overflow during BSON encoding in the Python native extension allows an application to write outside allocated buffer boundaries when encoding unusually large data.[emaillocker id="1283"]

CVE-2026-96750 (CVSS 7.1 — High): Shell script injection via server-supplied database name in Open shell enables attackers to inject malicious scripts into MongoDB Compass when users open the embedded shell.

CVE-2026-96744 (CVSS 7.1 — High): Unauthorized cache lock takeover via expression injection in lock owner values in integration for Laravel allows an attacker to take control of a lock, potentially leading to data corruption or unauthorized access.

CVE-2026-96748 (CVSS 6.5 — Medium): Connection redirection via percent-encoded delimiter injection in connection string hosts enables an attacker to add rogue database servers into client connection pools.

CVE-2026-96746 (CVSS 6.5 — Medium): Heap buffer overflow via mid-scan command list growth in client topology monitoring causes a heap buffer overflow during client topology monitoring, potentially leading to code execution or denial of service.

CVE-2026-96745 (CVSS 5.6 — Medium): PHP object injection via unsuppressible __pclass class inference in command monitoring events allows an attacker to inject malicious objects into the application's memory, potentially leading to unauthorized access or data tampering.

CVE-2026-96747 (CVSS 5.0 — Medium): Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encryption enables an attacker to force a connection to a local Unix socket, potentially leading to unauthorized access or denial of service.

RECOMMENDATIONS:

  • We recommend you to update MongoDB driver to below version:
  • MongoDB Python Driver (PyMongo) to version 4.18.2 or later.
  • MongoDB Compass to version 1.49.12 or later.
  • Laravel MongoDB to version 5.11.0 or later.
  • MongoDB C Driver to 1.30.12 or 2.5.5 or later.
  • MongoDB PHP Driver to 1.21.10, 2.1.10, or 2.5.3 or later.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu