CVE-2026-88026: MongoDB C# Driver

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected application. An authenticated user who can influence such a value may cause the application to return records beyond those intended by the original filter.

Affected products

  • MongoDB C# Driver: from 2.14.0, before 3.11.2 (fixed in 3.11.2)

Published 2026-09-10. Last modified 2026-09-29.