CVE-2026-106434: MongoDB Libmongocrypt

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

The explicit decryption component of MongoDB libmongocrypt can return an unrecognized encrypted payload unchanged instead of returning a decryption error. An actor who can modify stored encrypted fields, such as a database writer, server, or network intermediary, can cause an affected application to process the supplied bytes as decrypted plaintext.

Affected products

  • MongoDB Libmongocrypt: from 1.5.0, before 1.20.5 (fixed in 1.20.5)

Published 2026-10-08. Last modified 2026-10-08.