CVE-2026-93764

Source
https://cve.org/CVERecord?id=CVE-2026-93764
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93764.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93764
Published
2026-09-18T17:06:27Z
Modified
2026-09-26T03:48:39Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Plaintext storage of encrypted fields via skipped embedded models in encryption schema generation
Details

Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with no error or warning. A party with routine read access to the database, a backup, or the underlying data files may then see data that was meant to remain unreadable outside the application.

Database specific
{
    "cna_assigner": "mongodb",
    "cwe_ids": [
        "CWE-312"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93764.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "9.1.0"
                },
                {
                    "last_affected": "9.1.0"
                },
                {
                    "introduced": "9.0.0"
                },
                {
                    "last_affected": "9.0.11"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/mongodb/mongoid

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongoid
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:mongodb:mongoid:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:mongodb:mongoid:9.1.0:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.0.12"
        },
        {
            "introduced": "9.1.0"
        },
        {
            "last_affected": "9.1.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

9.*
9.1.0
v9.*
v9.0.0
v9.0.1
v9.0.10
v9.0.11
v9.0.2
v9.0.3
v9.0.4
v9.0.5
v9.0.6
v9.0.7
v9.0.8
v9.0.9
v9.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93764.json"