CVE-2026-81525: MongoDB PHP Driver
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a different storage location than the one the application intended.
Affected products
- MongoDB PHP Driver: before 1.21.6 (fixed in 1.21.6); from 2.0.0, before 2.4.1 (fixed in 2.4.1)
- MongoDB PHP Library: before 1.21.4 (fixed in 1.21.4); from 2.0.0, before 2.4.1 (fixed in 2.4.1)
Published 2026-08-27. Last modified 2026-09-29.