← Vulnerability feed

Vulnerability record · CVE-2026-84968 · published 3 September 2026

CVE-2026-84968: Mongodb php driver out-of-bounds read vulnerability

Mongodb · Php Driver

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.

6.9 CVSS 4.0 Medium EPSS 0.33% · top 76.4% CWE-125 · Out-of-bounds read
6.9CVSS 4.0 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
10 Sep 2026Last modified by NVD

Description

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-84968 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-7553Mongodb improper access control vulnerabilityIncorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Win…EPSS 0.26%7.5CVE-2021-32050Mongodb c\+\+ information exposure vulnerabilitySome MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The pu…EPSS 0.65%6.9CVE-2025-12119Mongodb c driver vulnerabilityA mongoc_bulk_operation_t may read invalid memory if large options are passed.EPSS 0.20%6.0CVE-2026-6811Mongodb php driver vulnerabilityStack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circum…EPSS 0.37%8.8CVE-2026-11645Google Chrome V8 out-of-bounds read and write enables sandbox code executionGoogle Chrome before 149.0.7827.103 contains an out-of-bounds read and write in the V8 JavaScript engine. A crafted HTML page can trigger the memory …KEVEPSS 2.2%analysed7.8CVE-2023-36424Windows Common Log File System Driver out-of-bounds read privilege escalationCVE-2023-36424 is an out-of-bounds read (CWE-125) in the Windows Common Log File System (CLFS) driver that allows elevation of privilege. It affects …KEVEPSS 12%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2026-84968), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.