HIGHVulnerability

CVE-2026-88033

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target.

Properties

severity
HIGH
score
8.3
cve_id
CVE-2026-88033
signal_observed_at
2026-09-18T13:45:43+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
published_at
2026-09-10T19:17:40.673
last_modified
2026-09-16T17:58:43.393

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements in Data Query Logic

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-88033 — Ninja Signal Threat Intelligence | Ninja Signal