Unauthorized Access Vulnerability in Google Cloud KMS API Affecting MongoDB
CVE-2026-84962

5.7MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84962?

A security flaw in the Google Cloud KMS API allows an unauthorized user, possessing key vault write access, to manipulate an authorized client's identity. This exploitation enables them to execute arbitrary authenticated API calls, effectively increasing access levels to critical database functions, compromising cloud key control and undermining client-side encryption measures.

Affected Version(s)

libmongocrypt 0 < 1.20.2

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.