Junglewise Threat Intelligence

CVE-2026-88024: MongoDB Rust Driver GridFS query injection in file identifier matching

CVE-2026-88024 · Severity: high · CVSS 8.3 · Published 2026-09-10

Vendors: MongoDB.

Executive brief

The MongoDB Rust Driver's GridFS component, used to store and retrieve large files in MongoDB, improperly handles file identifiers by treating them as query filters instead of literal values. An attacker who can control the file identifier in an application could access unintended files or delete all file chunks in a GridFS bucket, causing data loss and application failures.

Technical details

The vulnerability is an improper neutralization of special elements in data query logic (query injection) within the GridFS component of the MongoDB Rust Driver. When processing file identifiers, the driver fails to use strict equality matching (the $eq operator), allowing caller-supplied identifiers to be interpreted as MongoDB query conditions. An authenticated user who can influence the file identifier passed by an affected application can execute unintended database operations, including reading file content beyond the intended target or deleting all GridFS file chunks in the affected bucket. The fix, released in version 3.9.1, wraps all user-supplied GridFS file IDs with explicit $eq operators to enforce literal matching.

Affected products

  • MongoDB Rust Driver before 3.9.1

Timeline

  • 2026-09-10: disclosed: CVE-2026-88024 published
  • 2026-09-11: patched: Fix released in MongoDB Rust Driver 3.9.1

References

Related threats