Description
Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with no error or warning. A party with routine read access to the database, a backup, or the underlying data files may then see data that was meant to remain unreadable outside the application.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Compromise
Action: Apply Patch
AI Analysis

Impact

Mongoid creates client‑side field‑level encryption schemas. When embedded models declare encrypted fields, the encryption rules can be skipped, causing those fields to be stored as plaintext. The vulnerability allows the intended confidentiality of data to be completely lost, potentially exposing sensitive information.

Affected Systems

Mongoid, a Ruby ODM library for MongoDB provided by MongoDB Inc. The issue affects any application that uses Mongoid's client‑side field‑level encryption and relies on embedded models for encrypted fields. No exact version range is reported, so all installations using this feature should be considered vulnerable.

Risk and Exploitability

With a CVSS score of 7.1, the vulnerability is moderate to high severity. The EPSS score is under 1%, suggesting a low likelihood of active exploitation at the time of analysis, and it is not listed in the CISA KEV catalog. Nonetheless, the missing encryption is straightforward to detect by reading database documents, backup files, or raw data files, so the primary attack vector is an attacker with routine database read privileges or access to backups.

Generated by OpenCVE AI on September 19, 2026 at 16:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Mongoid to the latest patched version that includes proper encryption rule handling for embedded models.
  • Verify that your application's encryption schema generation includes all fields, especially in embedded documents, to confirm encryption is correctly applied.
  • Apply least‑privilege database access controls to limit routine read access only to application processes and ensure backups are encrypted and stored in a secured location.

Generated by OpenCVE AI on September 19, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:mongoid:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongoid:9.1.0:*:*:*:*:*:*:*

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongoid
Vendors & Products Mongodb
Mongodb mongoid

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with no error or warning. A party with routine read access to the database, a backup, or the underlying data files may then see data that was meant to remain unreadable outside the application.
Title Plaintext storage of encrypted fields via skipped embedded models in encryption schema generation
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-21T18:47:43.304Z

Reserved: 2026-09-18T16:51:42.828Z

Link: CVE-2026-93764

cve-icon Vulnrichment

Updated: 2026-09-21T18:47:39.318Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T18:18:35.330

Modified: 2026-09-24T16:00:04.347

Link: CVE-2026-93764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:07Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information