Input Validation Flaw in MongoDB's libmongocrypt Impacting Database Security
CVE-2026-81523
2LOW
What is CVE-2026-81523?
A vulnerability in MongoDB's libmongocrypt arises from a missing input validation during the automatic-encryption context setup. This flaw allows an attacker to use a caller-supplied database identifier without proper sanitization. The consequences may include an incorrect schema selection that could lead to unauthorized disclosure or alteration of sensitive information processed by the application. Ensuring robust validation mechanisms is essential to mitigate potential risks associated with this vulnerability.
Affected Version(s)
libmongocrypt 1.0.0 < 1.20.3