Unauthorized Access Vulnerability in Google Cloud KMS API Affecting MongoDB
CVE-2026-84962
5.7MEDIUM
What is CVE-2026-84962?
A security flaw in the Google Cloud KMS API allows an unauthorized user, possessing key vault write access, to manipulate an authorized client's identity. This exploitation enables them to execute arbitrary authenticated API calls, effectively increasing access levels to critical database functions, compromising cloud key control and undermining client-side encryption measures.
Affected Version(s)
libmongocrypt 0 < 1.20.2