Field-Level Encryption Vulnerability in MongoDB's Mongoid Library
CVE-2026-93764
7.1HIGH
What is CVE-2026-93764?
Mongoid, being a part of the MongoDB ecosystem, is susceptible to a significant flaw that may lead to the omission of crucial encryption rules for fields within embedded models. This gap occurs during the creation of the client-side field-level encryption schema. Consequently, when applications activate this feature, they risk storing values, intended for encryption, in an unprotected and readable format without generating any error or alert. As a result, anyone with access rights to the database, backups, or underlying files may view sensitive information that should otherwise remain encrypted and unreadable to unauthorized parties.
Affected Version(s)
Mongoid 9.1.0
Mongoid 9.0.0 <= 9.0.11