{"id":"CVE-2026-81525","summary":"Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP Driver","details":"The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a different storage location than the one the application intended.","modified":"2026-08-29T11:31:20.581895011Z","published":"2026-08-27T18:32:26.493Z","database_specific":{"cwe_ids":["CWE-943"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81525.json","cna_assigner":"mongodb"},"references":[{"type":"WEB","url":"https://github.com/mongodb/mongo-php-driver/releases/tag/1.21.6"},{"type":"WEB","url":"https://github.com/mongodb/mongo-php-driver/releases/tag/2.4.1"},{"type":"WEB","url":"https://github.com/mongodb/mongo-php-library/releases/tag/1.21.4"},{"type":"WEB","url":"https://github.com/mongodb/mongo-php-library/releases/tag/2.4.1"},{"type":"WEB","url":"https://jira.mongodb.org/browse/PHPLIB-1927"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81525.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81525"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb/mongo-php-driver","events":[{"introduced":"0"},{"introduced":"5a7adc35edf11107e8266146413d69b83de33d3f"},{"fixed":"dc49c0187ac54f42a994578d38b1bb8d0708a337"},{"fixed":"133eab57aee3bfb0d34ab8ee4bee6b314b31118e"},{"fixed":"3d7e69fd9ed9ed3893b5a3fcdc204c6864ef2241"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.21.4"},{"fixed":"1.21.6"},{"introduced":"2.0.0"},{"fixed":"2.4.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/mongodb/mongo-php-library","events":[{"introduced":"0"},{"fixed":"75754fbb53a980f0e9b1d5ddfff99ee4f44463c2"},{"fixed":"b72cc2ecf4a11d3871f78a119a8f3cc7ab6d6c29"}],"database_specific":{"source":"REFERENCES"}}],"versions":["2.4.0","2.2.0","1.21.5","1.21.4","1.21.2","1.21.1","1.21.0","1.18.0","1.17.0","1.15.0","1.14.0","1.14.0beta1","1.13.0","1.12.0","1.11.0","1.11.0alpha1","1.10.0alpha1","1.6.0RC1","1.6.0alpha3","1.6.0alpha2","1.6.0alpha1","1.5.0","1.4.0RC1","1.4.0beta1","1.3.1","1.3.0","1.3.0RC1","1.3.0beta2","1.3.0beta1","1.2.3","1.2.2","1.2.1","1.2.0","1.2.0alpha3","1.2.0alpha2","1.2.0alpha1","1.1.4","1.1.3","1.1.2","1.1.1","1.1.0","1.0.0","1.0.0RC0","1.0.0beta2","1.0.0beta1","1.0.0alpha2","1.0.0alpha1","0.6.3","0.6.2","0.6.1","0.6.0","0.5.1","0.5.0","0.4.1","0.4.0","0.3.1","0.3.0","0.2.0","0.1.5","0.1.4","0.1.3","0.1.2","0.1.1","0.1.0","2.3.0","1.21.3","2.1.0","2.0.0","1.19.0","1.16.0","1.13.0-beta1","1.10.0","1.9.0","1.9.0-alpha1","1.8.0-RC1","1.6.0","1.7.0-beta1","1.4.2","1.4.1","1.4.0","1.2.0-alpha1","1.1.0-alpha1","1.0.1","1.0.0-beta2","1.0.0-beta1","1.0.0-alpha1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81525.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}