CVE WATCH / VULNERABILITY DETAIL

CVE-2026-96744

HIGHCVSS 7.1NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than as a literal value. An authenticated user who can influence th

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-96744 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-96744

HIGHCVSS 7.1NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than as a literal value. An authenticated user who can influence th

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]