CVE-2026-81525: Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP Driver

Published Aug 27, 2026
·
Updated

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a different storage location than the one the application intended.

Affected Software

1 affected component
MongoDB PHP Driver

Event History

Aug 27, 2026
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are required for exploitation?

An attacker needs network access and low-level privileges, with no user interaction required. The application must incorporate attacker-controlled text into namespace identifiers used by the PHP client library.

2

What is the practical impact for affected applications?

Database operations may be silently redirected to a storage location other than the one intended by the application. This can result in high-impact confidentiality and integrity consequences, while no availability impact is indicated.

3

How can I identify applications that may be exposed?

Review PHP applications using the MongoDB PHP Driver or MongoDB PHP library for code that builds database or collection namespace identifiers from request data or other untrusted input. Pay particular attention to namespace values that are not strictly validated before being passed to database operations.

4

What release information is available for remediation planning?

The provided references include MongoDB PHP Library release 2.4.1 and MongoDB PHP Driver release 1.21.7. Compare deployed components with those release references and review the associated release information before updating.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203