Executive brief
MongoDB's client-side encryption library allows an attacker with write access to the key vault to trick legitimate applications into making unauthorized API calls to Google Cloud KMS under the legitimate user's credentials. This bypasses the application's own encryption protections and gives attackers control over the encryption keys that protect sensitive data.
Technical details
The vulnerability exists in MongoDB's Crypt library (mongocrypt) and involves improper validation of key vault contents. An attacker with write access to the MongoDB key vault can inject or modify data that causes an authorized client application to issue arbitrary authenticated API calls to Google Cloud KMS using the client's own identity. This escalates limited database-level write access into cloud key management privileges. The attack requires the legitimate client to be already connected and authenticated to both MongoDB and Google Cloud KMS; the vulnerability is triggered when the client processes malicious data from the key vault. No patch status is currently documented in the available advisory information.
Affected products
- MongoDB mongocrypt
Timeline
- 2026-09-03: disclosed