CVE-2026-96748

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-177

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-28: 109-28
Referenced assets1 URL
By indicator
Full discourse1 post
  • ThreatWire@ThreatWire_

    🚨 SECURITY UPDATE: MongoDB has patched 7 vulnerabilities across its driver ecosystem and related tools. The affected components include PyMongo, C Driver, PHP Driver, MongoDB Compass and Laravel MongoDB. The most severe issues are: • CVE-2026-96748 — CVSS 8.3 • CVE-2026-96746 — CVSS 8.3 The vulnerabilities can impact confidentiality, integrity, availability and, in some cases, allow arbitrary code execution. 🔴 Update affected MongoDB components to their latest patched versions. No active exploitation has been reported at this time. Source: https://www.mongodb.com/resources/products/capabilities/security #CVE #CyberSecurity #MongoDB #InfoSec #DevSecOps

    00020147
    1.6K followersView on X

Explore more