CVE-2026-88027
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
10/09/2026
Last modified:
29/09/2026
Description
Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence such an identifier may delete all embedded documents in a targeted record or overwrite an embedded document other than the intended target.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mongodb:laravel_mongodb:*:*:*:*:*:*:*:* | 4.0.0 (including) | 5.11.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page


