{"id":"CVE-2026-96744","summary":"Unauthorized cache lock takeover via expression injection in lock owner values in MongoDB integration for Laravel","details":"Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than as a literal value. An authenticated user who can influence the owner value an application uses when acquiring or restoring a lock may take over or prematurely expire a lock held by another process, which can lead to duplicated or conflicting operations.","modified":"2026-09-26T03:48:30.134012508Z","published":"2026-09-24T15:51:12.113Z","database_specific":{"cna_assigner":"mongodb","cwe_ids":["CWE-943"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96744.json"},"references":[{"type":"WEB","url":"https://github.com/mongodb/laravel-mongodb/releases/tag/5.11.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96744.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96744"},{"type":"FIX","url":"https://github.com/mongodb/laravel-mongodb/pull/3579"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb/laravel-mongodb","events":[{"introduced":"64d6dc05a8f08d9cf09f6b2d54f891a1692f6181"},{"fixed":"0634653039468ceb0268a69192bdac64469ed043"}],"database_specific":{"extracted_events":[{"introduced":"4.3.0"},{"fixed":"5.11.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["5.10.0","5.9.1","5.9.0","5.8.0","5.7.0","5.6.0","5.5.0","5.4.0","5.3.0","5.2.0","5.1.0","5.0.0-rc1","4.7.0","4.6.0","4.5.0","4.4.0","4.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96744.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"}]}