Laravel MongoDB Integration Improper Neutralization of Special Elements
CVE-2026-88028 Published on September 10, 2026
Unauthorized document disclosure via query-operator injection in polymorphic relation identifiers in MongoDB integration for Laravel
Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence a stored relation identifier may cause an affected application to return a document other than the intended relation target.
Vulnerability Analysis
CVE-2026-88028 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Improper Neutralization of Special Elements in Data Query Logic
The application generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
Products Associated with CVE-2026-88028
Want to know whenever a new CVE is published for MongoDB? stack.watch will email you.
Affected Versions
Laravel MongoDB (PHP):- Version 1.2.0 and below 5.11.0 is affected.