Heap-Based Buffer Overflow in MongoDB C Driver on Windows Platform
CVE-2026-93393

9.2CRITICAL

Key Information:

Vendor

MongoDB

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-93393?

A vulnerability exists in the MongoDB C Driver's TLS transport layer for the Windows platform, allowing a remote endpoint to exploit a heap-based buffer overflow. This occurs when the driver processes incoming encrypted traffic, potentially allowing an attacker to manipulate the connection, which leads to writing data outside the allocated memory bounds. Since the vulnerability can be triggered before any application-level authentication, no user interaction is required. Exploitation may result in memory corruption, disclosure of adjacent memory, or even termination of the client process.

Affected Version(s)

C Driver Windows 2.4.0

C Driver Windows 2.3.0 <= 2.3.3

C Driver Windows 2.2.0 <= 2.2.4

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.