CVE-2026-106434
Awaiting Analysis Awaiting Analysis - Queue

MongoDB libmongocrypt Decryption Bypass Vulnerability

Vulnerability report for CVE-2026-106434, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MongoDB, Inc.

Description

The explicit decryption component of MongoDB libmongocrypt can return an unrecognized encrypted payload unchanged instead of returning a decryption error. An actor who can modify stored encrypted fields, such as a database writer, server, or network intermediary, can cause an affected application to process the supplied bytes as decrypted plaintext.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
MongoDB libmongocrypt 1.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in MongoDB libmongocrypt allows an attacker who can modify encrypted fields to bypass decryption checks. Instead of rejecting unrecognized encrypted payloads, the system returns them as plaintext, potentially exposing sensitive data to unauthorized processing.

Detection Guidance

This vulnerability may be detected by monitoring for unexpected decryption behavior in MongoDB libmongocrypt. Check logs for instances where encrypted payloads are processed as plaintext without errors. Review database write operations for unauthorized modifications to encrypted fields.

Impact Analysis

If you use MongoDB with encrypted fields, an attacker with write access to your database or network could inject malicious payloads. This might lead to data corruption, unauthorized data exposure, or application logic manipulation if the system processes the injected data as valid.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR or HIPAA by allowing unauthorized access or modification of encrypted sensitive data. Compliance may be compromised if encrypted fields are not properly protected, leading to potential data breaches or unauthorized processing.

Mitigation Strategies

Update MongoDB libmongocrypt to the latest patched version. Restrict database write permissions to prevent unauthorized modifications to encrypted fields. Monitor network traffic for suspicious activity between clients and MongoDB servers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106434. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart