CVE-2026-81525: MongoDB PHP Driver

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a different storage location than the one the application intended.

Affected products

  • MongoDB PHP Driver: before 1.21.6 (fixed in 1.21.6); from 2.0.0, before 2.4.1 (fixed in 2.4.1)
  • MongoDB PHP Library: before 1.21.4 (fixed in 1.21.4); from 2.0.0, before 2.4.1 (fixed in 2.4.1)

Published 2026-08-27. Last modified 2026-09-29.