Field-Level Encryption Vulnerability in MongoDB's Mongoid Library
CVE-2026-93764

7.1HIGH

Key Information:

Vendor

MongoDB

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93764?

Mongoid, being a part of the MongoDB ecosystem, is susceptible to a significant flaw that may lead to the omission of crucial encryption rules for fields within embedded models. This gap occurs during the creation of the client-side field-level encryption schema. Consequently, when applications activate this feature, they risk storing values, intended for encryption, in an unprotected and readable format without generating any error or alert. As a result, anyone with access rights to the database, backups, or underlying files may view sensitive information that should otherwise remain encrypted and unreadable to unauthorized parties.

Affected Version(s)

Mongoid 9.1.0

Mongoid 9.0.0 <= 9.0.11

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.