CVE-2026-88027: MongoDB's Laravel MongoDB (PHP) integration mishandles embedded-document identifiers, letting an authenticated user delete or overwrite embedded documents in a targeted record via quer

CVE-2026-88027: MongoDB's Laravel MongoDB (PHP) integration mishandles embedded-document identifiers, letting an authenticated user delete or overwrite embedded documents in a targeted record via query-operator injection. Affected versions 4.0.0 up to 5.11.0. Fixed in 5.11.0. No exploitation confirmed. https://www. cve.org/CVERecord?id=CVE-2026- 88027 # infosec # cybersecurity

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-88027: MongoDB's Laravel MongoDB (PHP) integration mishandles embedded-document identifiers, letting an authenticated user delete or overwrite embedded documents in a targeted record via quer

mastodon:infosec-exchangeother19d ago kagi ↗

CVE-2026-88027: MongoDB's Laravel MongoDB (PHP) integration mishandles embedded-document identifiers, letting an authenticated user delete or overwrite embedded documents in a targeted record via query-operator injection. Affected versions 4.0.0 up to 5.11.0. Fixed in 5.11.0. No exploitation confirmed. https://www. cve.org/CVERecord?id=CVE-2026- 88027 # infosec # cybersecurity