CVE-2026-88035
CVE-2026-88035 is a medium-severity vulnerability in Mongodb C Driver with a CVSS 3.x base score of 4.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-190.
Key facts
- Severity: Medium (CVSS 3.x base score 4.7)
- CVSS v4: 5.7
- EPSS exploit prediction: 0% (1st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-190
- Affected product: Mongodb C Driver
- Published:
- Last modified:
Description
A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.
Frequently asked questions
- What is CVE-2026-88035?
- A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.
- How severe is CVE-2026-88035?
- CVE-2026-88035 has a CVSS 3.x base score of 4.7, rated medium severity. It is exploitable over local access with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2026-88035 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (1st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-88035?
- CVE-2026-88035 affects Mongodb C Driver. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-88035?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-88035 published?
- CVE-2026-88035 was published on 2026-09-10 and last updated on 2026-09-16.
References
Affected products (1)
- cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*
More vulnerabilities in Mongodb C Driver
- CVE-2026-88036 — High (CVSS 8.3): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can…
- CVE-2026-6691 — High (CVSS 7.8): The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling…
- CVE-2024-7553 — High (CVSS 7.3): Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the…
- CVE-2025-12119 — Medium (CVSS 6.8): A mongoc_bulk_operation_t may read invalid memory if large options are passed.
- CVE-2020-12135 — Medium (CVSS 5.5): bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In…
- CVE-2023-0437 — Medium (CVSS 5.3): When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an…
All CVEs affecting Mongodb C Driver →
Other CWE-190 (Integer Overflow or Wraparound) vulnerabilities
- CVE-2026-4689 — Critical (CVSS 10.0): Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was…
- CVE-2026-24814 — Critical (CVSS 10.0): Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is…
- CVE-2025-64721 — Critical (CVSS 10.0): Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions…
- CVE-2015-5108 — Critical (CVSS 10.0): Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC…
- CVE-2015-5097 — Critical (CVSS 10.0): Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC…
- CVE-2013-2555 — Critical (CVSS 10.0): Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before…
Browse all CWE-190 (Integer Overflow or Wraparound) vulnerabilities →