CVE-2026-106434: MongoDB Libmongocrypt
Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.
The explicit decryption component of MongoDB libmongocrypt can return an unrecognized encrypted payload unchanged instead of returning a decryption error. An actor who can modify stored encrypted fields, such as a database writer, server, or network intermediary, can cause an affected application to process the supplied bytes as decrypted plaintext.
Affected products
- MongoDB Libmongocrypt: from 1.5.0, before 1.20.5 (fixed in 1.20.5)
Published 2026-10-08. Last modified 2026-10-08.