MEDIUMVulnerability

CVE-2026-84968

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.

Properties

severity
MEDIUM
score
5.3
cve_id
CVE-2026-84968
signal_observed_at
2026-09-15T21:20:01+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
published_at
2026-09-03T18:17:33.010
last_modified
2026-09-10T20:39:21.967

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Read

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84968 — Ninja Signal Threat Intelligence | Ninja Signal