CVE-2026-88026: MongoDB C# Driver
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected application. An authenticated user who can influence such a value may cause the application to return records beyond those intended by the original filter.
Affected products
- MongoDB C# Driver: from 2.14.0, before 3.11.2 (fixed in 3.11.2)
Published 2026-09-10. Last modified 2026-09-29.