Decryption Flaw in MongoDB libmongocrypt Allows Manipulation of Encrypted Payloads
CVE-2026-106434
5.3MEDIUM
What is CVE-2026-106434?
The MongoDB libmongocrypt contains a vulnerability in its explicit decryption component, where it may fail to return errors for unrecognized encrypted payloads. Instead of indicating a decryption failure, the system can inadvertently process modified encrypted data as valid plaintext. This issue poses a risk to applications that trust the integrity of decrypted data, potentially allowing malicious actors with access to input encrypted fields to manipulate data without detection. Users should validate trusted deployments and assess the implications of this vulnerability on their systems.
Affected Version(s)
libmongocrypt 1.5.0 < 1.20.5