CVE-2026-81525
Analyzed
Analyzed - Analysis Complete
PHP MongoDB Client Library Namespace Injection Vulnerability
Vulnerability report for CVE-2026-81525, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-27
Last updated on: 2026-09-29
Assigner: MongoDB, Inc.
Description
Description
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a different storage location than the one the application intended.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mongodb | php_driver | From 2.0.0 (inc) to 2.4.1 (exc) |
| mongodb | php_driver | to 1.21.6 (exc) |
| mongodb | php_library | to 1.21.4 (exc) |
| mongodb | php_library | From 2.0.0 (inc) to 2.4.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-943 | The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query. |