Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/PHPLARA-265 |
|
Thu, 10 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence such an identifier may delete all embedded documents in a targeted record or overwrite an embedded document other than the intended target. | |
| Title | Mass deletion and overwrite of embedded documents via query-operator injection in embedded record keys in MongoDB integration for Laravel | |
| Weaknesses | CWE-943 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-10T18:22:21.724Z
Reserved: 2026-09-09T19:49:39.183Z
Link: CVE-2026-88027
Updated: 2026-09-10T18:22:14.390Z
Status : Awaiting Analysis
Published: 2026-09-10T18:18:13.030
Modified: 2026-09-10T19:54:25.810
Link: CVE-2026-88027
No data.
OpenCVE Enrichment
No data.
-
CWE-943
Improper Neutralization of Special Elements in Data Query Logic