Threat Advisory

MongoDB GridFS Data Disclosure via Query-Operator Injection

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability affecting mongodb/mongodb versions >= 1.1.0, < 1.21.5 affecting mongodb/mongodb versions >= 2.0.0, < 2.4.2, CVE-2026-88023, exists in the MongoDB PHP Library due to improper neutralization of special elements in data query logic in the GridFS component. This flaw allows an authenticated user who can influence the identifier passed by an affected application to obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target. An attacker can exploit this flaw via a caller-supplied structured file identifier that is interpreted as a query condition rather than as a literal identifier. This vulnerability has a CVSS v4 score of 6.1, with an attack vector of network and attack complexity of low. The business impact includes data disclosure and deletion, which can lead to unauthorized access to sensitive information or loss of critical data.

RECOMMENDATION:

We recommend you to update MongoDB to version 1.24.5 or 2.4.2.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability affecting mongodb/mongodb versions >= 1.1.0, < 1.21.5 affecting mongodb/mongodb versions >= 2.0.0, < 2.4.2, CVE-2026-88023, exists in the MongoDB PHP Library due to improper neutralization of special elements in data query logic in the GridFS component. This flaw allows an authenticated user who can influence the identifier passed by an affected application to obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target. An attacker can exploit this flaw via a caller-supplied structured file identifier that is interpreted as a query condition rather than as a literal identifier. This vulnerability has a CVSS v4 score of 6.1, with an attack vector of network and attack complexity of low. The business impact includes data disclosure and deletion, which can lead to unauthorized access to sensitive information or loss of critical data.

RECOMMENDATION:

We recommend you to update MongoDB to version 1.24.5 or 2.4.2.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu