Junglewise Threat Intelligence

CVE-2026-93763: MongoDB object-document mapper client-side encryption configuration bypass

CVE-2026-93763 · Severity: medium · CVSS 6.5 · Published 2026-09-18

Executive brief

MongoDB's object-document mapper has a flaw in how it generates encryption settings for client-side field-level encryption. Fields that applications intended to encrypt are instead stored in plaintext in the database, allowing anyone with basic read access to view sensitive data that should have been protected. This could expose confidential information like passwords, payment details, or personal identification numbers.

Technical details

The vulnerability is a protection mechanism failure in the encryption configuration generation logic of an object-document mapper, causing marked fields to bypass client-side field-level encryption (CSFLE) and be written in cleartext. An unauthenticated or low-privileged database read results in disclosure of sensitive plaintext values. No evidence indicates active exploitation, but the issue requires application-level remediation to re-enable encryption for affected fields.

Affected products

  • MongoDB ODM (Object-Document Mapper)

Timeline

  • 2026-09-18: disclosed

References