CVE-2026-84962: MongoDB Libmongocrypt
Medium severity, CVSS 4.2. EPSS: 0.2% chance of exploitation in the next 30 days.
An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption.
Affected products
- MongoDB Libmongocrypt: before 1.20.2 (fixed in 1.20.2)
Published 2026-09-03. Last modified 2026-09-17.