Description
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

A flaw in the encryption configuration generator of the Mongoid object‑document mapper can lead to fields that are intended for client‑side field‑level encryption being persisted in cleartext. The bug causes unresolved database names in the encryption schema map, and no error or warning is emitted. As a result, data that was expected to be protected ends up stored unencrypted, allowing an unauthorized party to read it later.

Affected Systems

The vulnerability affects Mongoid, the ODM provided by MongoDB Inc. No specific product versions were listed in the advisory, so any release that includes the described encryption configuration mechanism may be at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests that, in practice, exploitation is unlikely, and the flaw is not currently listed in the CISA KEV catalog. Nevertheless, an attacker with ordinary read access to the database can retrieve sensitive data that was meant to be encrypted, leading to unintended disclosure. The attack vector is inferred to be an internal or privileged user who gains read access to the database, since no network or remote execution path is described.

Generated by OpenCVE AI on September 19, 2026 at 16:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Mongoid patch that fixes the encryption schema map bug.
  • Verify that all fields marked for client‑side encryption are properly listed in the schema and that database names are resolved correctly.
  • Review configuration files for any unresolved database references and explicitly set them to the intended values.
  • Audit the database to locate any cleartext fields that should be encrypted and reconfigure them to use encryption.
  • Restrict database read permissions to only the users who truly need access and monitor for unauthorized reads.

Generated by OpenCVE AI on September 19, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:mongoid:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongoid:9.1.0:*:*:*:*:*:*:*

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongoid
Vendors & Products Mongodb
Mongodb mongoid

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.
Title Silent plaintext persistence via unresolved callable database name in encryption schema map
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-21T18:16:01.990Z

Reserved: 2026-09-18T16:51:41.846Z

Link: CVE-2026-93763

cve-icon Vulnrichment

Updated: 2026-09-21T18:14:39.119Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T18:18:35.193

Modified: 2026-09-24T16:00:39.703

Link: CVE-2026-93763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:45:16Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information