Junglewise Threat Intelligence

CVE-2026-88034: MongoDB C++ Driver GridFS injection in file identifier query

CVE-2026-88034 · Severity: high · CVSS 8.3 · Published 2026-09-10

Technologies: MongoDB C Driver. Vendors: MongoDB.

Executive brief

The MongoDB C++ Driver's GridFS component, which handles large file storage within MongoDB databases, contains a flaw that allows user-supplied file identifiers to be interpreted as database queries rather than literal values. An authenticated attacker who controls the file identifier used by an application could read files outside the intended scope or delete all file chunks in a storage bucket, rendering stored data inaccessible and potentially causing data loss.

Technical details

The vulnerability is an improper neutralization of special elements in data query logic (CWE-89 equivalent, injection-style flaw) in the GridFS component of the MongoDB C++ Driver. The root cause is that user-supplied file identifiers are not properly escaped or explicitly matched using query operators; they are concatenated into database query conditions, allowing attackers to inject MongoDB query syntax. An authenticated user with the ability to influence the file ID parameter passed to GridFS methods can exploit this to either retrieve unintended file content or delete file chunks across the bucket. The fix, available in version 4.5.3, implements explicit exact-match queries using the $eq operator for all user-supplied GridFS file IDs in database commands.

Affected products

  • MongoDB C++ Driver before 4.5.3

Timeline

  • 2026-09-10: disclosed
  • 2026-09-11: patched: Fix released in version 4.5.3

References

Related threats