Laravel MongoDB Integration: Improper Neutralization of Special Elements
CVE-2026-88027 Published on September 10, 2026
Mass deletion and overwrite of embedded documents via query-operator injection in embedded record keys in MongoDB integration for Laravel
Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence such an identifier may delete all embedded documents in a targeted record or overwrite an embedded document other than the intended target.
Vulnerability Analysis
CVE-2026-88027 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Improper Neutralization of Special Elements in Data Query Logic
The application generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
Products Associated with CVE-2026-88027
Want to know whenever a new CVE is published for MongoDB? stack.watch will email you.
Affected Versions
Laravel MongoDB (PHP):- Version 4.0.0 and below 5.11.0 is affected.