DEBIAN-CVE-2026-88036
Dashboard / Vulnerabilities / DEBIAN-CVE-2026-88036
Summary:
Details: Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.
Affected packages
Package
Name: mongo-c-driver
Purl: pkg:deb/debian/mongo-c-driver?arch=source&distro=bookworm
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
1.23.1-1
1.23.1-1+deb12u1
1.23.1-1+deb12u2
1.23.1-1+deb12u3
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
