Decryption Flaw in MongoDB libmongocrypt Allows Manipulation of Encrypted Payloads
CVE-2026-106434

5.3MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 October 2026

What is CVE-2026-106434?

The MongoDB libmongocrypt contains a vulnerability in its explicit decryption component, where it may fail to return errors for unrecognized encrypted payloads. Instead of indicating a decryption failure, the system can inadvertently process modified encrypted data as valid plaintext. This issue poses a risk to applications that trust the integrity of decrypted data, potentially allowing malicious actors with access to input encrypted fields to manipulate data without detection. Users should validate trusted deployments and assess the implications of this vulnerability on their systems.

Affected Version(s)

libmongocrypt 1.5.0 < 1.20.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.