CVE-2026-96745 MEDIUM

CVE-2026-96745: PHP object injection via unsuppressible __pclass class inference in command monitoring events

Vendor Mongodb
Product PHP Driver
Weakness CWE-502 · Unsafe deserialization
Published September 24, 2026
Last update September 24, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database operation, an unauthenticated party who controls that data may cause an application class implementing the driver's persistable interface to be instantiated and its unserialization method invoked with the supplied data. The resulting impact depends on the classes available in the application.

Key dates

02Disclosure timeline

September 24, 2026 CVE published

Related vulnerabilities

04Related CVE