Description
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments.
Published: 2026-09-17
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential compromise
Action: Apply TLS
AI Analysis

Impact

A flaw in libmongoc’s SCRAM authentication implementation causes the client to proceed with the handshake and transmit the client proof even when the server’s first message contains a mismatched nonce. This allows an attacker who can intercept or inject traffic to supply a crafted server-first message with a contrived salt and low iteration count, enabling the attacker to capture the client proof and perform offline password cracking. The weakness is a form of improper input validation (CWE-303).

Affected Systems

MongoDB Inc. C Driver

Risk and Exploitability

The CVSS base score is 6.3, indicating a moderate severity. The EPSS score is less than 1 %, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. However, the attack requires a man‑in‑the‑middle position, which may be realistic in untrusted networks. The vulnerability is mitigated by using TLS, which is standard in production deployments.

Generated by OpenCVE AI on September 18, 2026 at 23:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Configure the MongoDB C driver to require TLS/SSL so the SCRAM handshake never travels unencrypted.
  • Upgrade the libmongoc library to the latest MongoDB‑supported release once an official patch is available.
  • Restrict client–server traffic to a secure network segment and monitor for anomalous SCRAM authentication activity.

Generated by OpenCVE AI on September 18, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb c Driver
Vendors & Products Mongodb
Mongodb c Driver

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments.
Title libmongoc SCRAM client nonce-validation bypass
Weaknesses CWE-303
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb C Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-18T14:31:41.209Z

Reserved: 2026-09-17T20:11:00.595Z

Link: CVE-2026-93394

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:20.847Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T21:17:56.307

Modified: 2026-09-25T20:33:17.027

Link: CVE-2026-93394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:45:15Z

Weaknesses
  • CWE-303

    Incorrect Implementation of Authentication Algorithm