CVE-2026-106433
Awaiting Analysis Awaiting Analysis - Queue

Improper State Management in MongoDB libmongocrypt

Vulnerability report for CVE-2026-106433, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MongoDB, Inc.

Description

Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault documents, or a server that returns such a key document, can cause invalid memory access and invalid frees in the client process. This can terminate the application or corrupt process memory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
MongoDB libmongocrypt 1.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper state management in MongoDB libmongocrypt. When a key document contains duplicate masterKey fields, the system may incorrectly treat provider-specific data as an incompatible type during cleanup. This leads to invalid memory access and invalid frees in the client process, potentially causing the application to terminate or corrupt memory.

Detection Guidance

This vulnerability involves improper state management in MongoDB libmongocrypt, leading to memory corruption. Detection requires checking for crashes or memory corruption in applications using libmongocrypt, particularly when handling key vault documents with duplicate masterKey fields.

Impact Analysis

An authenticated attacker who can modify key vault documents or a malicious server returning such documents could exploit this flaw. This may result in application crashes, memory corruption, or arbitrary code execution in the client process, depending on the environment and usage.

Compliance Impact

This vulnerability could lead to memory corruption or application termination, potentially causing data leaks or integrity issues. Such impacts may violate GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information if exploited.

Mitigation Strategies

Update libmongocrypt to the latest patched version immediately. Review key vault documents for duplicate masterKey fields and remove any duplicates. Monitor applications for crashes or memory corruption as a sign of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106433. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart