CVE-2026-93763
6.5 MEDIUMPublished 2026-09-18 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-312
Vendors
mongodb
Products
mongoid
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-100288
- MEDIUMCVE-2026-100581PoC
- MEDIUMCVE-2026-100862PoC
- CRITICALCVE-2026-15721
- HIGHCVE-2026-55997PoC
- UNSCOREDCVE-2026-63207PoC
- MEDIUMCVE-2026-63406PoC
- UNSCOREDCVE-2026-67221PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.