Description
The explicit decryption component of MongoDB libmongocrypt can return an unrecognized encrypted payload unchanged instead of returning a decryption error. An actor who can modify stored encrypted fields, such as a database writer, server, or network intermediary, can cause an affected application to process the supplied bytes as decrypted plaintext.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Data Integrity
Action: Patch
AI Analysis

Impact

The library provides explicit decryption that, when encountering an unrecognized encrypted payload, returns the raw bytes unchanged instead of signaling a decryption failure. This flaw means an attacker who can alter stored encrypted data can cause the application to treat the corrupted blob as a legitimate plaintext value, potentially leading to incorrect application behavior or data corruption. The weakness arises from improper error handling during decryption (CWE-354).

Affected Systems

This vulnerability affects the MongoDB libmongocrypt component. No specific version range is listed, so all releases of MongoDB libmongocrypt that have not yet absorbed the fix are potentially impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium risk. The EPSS score is not available, so the public exploitation probability is unclear, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to modify encrypted fields, such as a database writer, an unauthorized server, or a network intermediary. The likely attack vector is through compromised write access or tampering with data in transit; if an attacker succeeds, the affected application could process the tampered payload as plaintext, leading to data integrity issues.

Generated by OpenCVE AI on October 8, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libmongocrypt to the latest version that includes the patch for MONGOCRYPT-966.
  • Ensure the application checks and handles decryption errors appropriately, so that any failure from libmongocrypt does not lead to the use of unverified data.
  • Restrict write permissions to encrypted fields to trusted services and consider implementing integrity auditing to detect unauthorized modifications.

Generated by OpenCVE AI on October 8, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb libmongocrypt
Vendors & Products Mongodb
Mongodb libmongocrypt

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description The explicit decryption component of MongoDB libmongocrypt can return an unrecognized encrypted payload unchanged instead of returning a decryption error. An actor who can modify stored encrypted fields, such as a database writer, server, or network intermediary, can cause an affected application to process the supplied bytes as decrypted plaintext.
Title Unrecognized payload acceptance in explicit decryption in MongoDB libmongocrypt
Weaknesses CWE-354
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Libmongocrypt
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-08T19:30:49.513Z

Reserved: 2026-10-06T16:40:35.016Z

Link: CVE-2026-106434

cve-icon Vulnrichment

Updated: 2026-10-08T19:30:46.003Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:16:59.390

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-106434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-354

    Improper Validation of Integrity Check Value