A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/MONGOID-5984 |
|
History
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information. | |
| Title | Silent plaintext persistence via unresolved callable database name in encryption schema map | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-18T17:10:24.616Z
Reserved: 2026-09-18T16:51:41.846Z
Link: CVE-2026-93763
No data.
Status : Awaiting Analysis
Published: 2026-09-18T18:18:35.193
Modified: 2026-09-18T19:05:01.127
Link: CVE-2026-93763
No data.
OpenCVE Enrichment
No data.
Weaknesses