Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb php Driver |
|
| Vendors & Products |
Mongodb
Mongodb php Driver |
Thu, 24 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 24 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database operation, an unauthenticated party who controls that data may cause an application class implementing the driver's persistable interface to be instantiated and its unserialization method invoked with the supplied data. The resulting impact depends on the classes available in the application. | |
| Title | PHP object injection via unsuppressible __pclass class inference in command monitoring events | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-24T18:18:09.854Z
Reserved: 2026-09-23T15:45:49.109Z
Link: CVE-2026-96745
Updated: 2026-09-24T17:22:35.239Z
Status : Awaiting Analysis
Published: 2026-09-24T16:17:27.293
Modified: 2026-09-24T21:04:40.340
Link: CVE-2026-96745
No data.
OpenCVE Enrichment
Updated: 2026-09-24T22:15:16Z