Description
Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database operation, an unauthenticated party who controls that data may cause an application class implementing the driver's persistable interface to be instantiated and its unserialization method invoked with the supplied data. The resulting impact depends on the classes available in the application.
Published: 2026-09-24
Score: 6.3 Medium
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb php Driver
Vendors & Products Mongodb
Mongodb php Driver

Thu, 24 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 18:30:00 +0000


Thu, 24 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database operation, an unauthenticated party who controls that data may cause an application class implementing the driver's persistable interface to be instantiated and its unserialization method invoked with the supplied data. The resulting impact depends on the classes available in the application.
Title PHP object injection via unsuppressible __pclass class inference in command monitoring events
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Php Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-24T18:18:09.854Z

Reserved: 2026-09-23T15:45:49.109Z

Link: CVE-2026-96745

cve-icon Vulnrichment

Updated: 2026-09-24T17:22:35.239Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-24T16:17:27.293

Modified: 2026-09-24T21:04:40.340

Link: CVE-2026-96745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T22:15:16Z

Weaknesses