Junglewise Threat Intelligence

CVE-2026-88022: MongoDB Integration for Laravel query injection in where method

CVE-2026-88022 · Severity: high · CVSS 7.7 · Published 2026-09-10

Vendors: MongoDB.

Executive brief

The MongoDB integration for Laravel contains a query injection vulnerability in its where method when used with the equality operator. An attacker who can control query input can craft malicious array values that are interpreted as MongoDB query operators instead of literal values, allowing unauthorized data access or deletion beyond the intended scope. This affects any Laravel application using this driver and accepting user input in database queries.

Technical details

The vulnerability is a query injection flaw in the query builder's where() method. When the three-argument form where($column, '=', $value) or where($column, 'eq', $value) is called with an array $value, the array is embedded directly into the MongoDB filter without proper escaping, causing MongoDB to interpret it as an operator document rather than a literal value. The same issue affects internal methods find($id) and delete($id) which internally use where('_id', '=', $id). An attacker who can inject an operator-shaped array (e.g., ['$ne' => null]) can bypass field-level lookups or delete arbitrary documents. The fix, released in version 5.11.0, wraps array values in an explicit $eq operator for the three-argument form to force literal comparison. The two-argument form where($column, $array) retains its original behavior for intentional operator document construction.

Affected products

  • MongoDB Laravel MongoDB before 5.11.0

Timeline

  • 2026-09-10: disclosed
  • 2026-09-10: patched: Fixed in version 5.11.0

References

Related threats