← Vulnerability feed

Vulnerability record · CVE-2026-93394 · published 17 September 2026

CVE-2026-93394: Mongodb c driver vulnerability

Mongodb · C Driver

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments.

6.3 CVSS 4.0 Medium EPSS 0.32% · top 77.3% CWE-303 · CWE-303
6.3CVSS 4.0 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
25 Sep 2026Last modified by NVD

Description

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jira.mongodb.org/browse/CDRIVER-6315 Permissions Required

Track CVE-2026-93394 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-6691Mongodb c driver classic buffer overflow vulnerabilityThe MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before…EPSS 0.18%8.2CVE-2026-84964Mongodb c driver double free vulnerabilityA double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client …EPSS 0.26%7.8CVE-2024-7553Mongodb improper access control vulnerabilityIncorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Win…EPSS 0.26%7.5CVE-2023-0437Mongodb c driver vulnerabilityWhen calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affe…EPSS 1.1%7.5CVE-2021-32050Mongodb c\+\+ information exposure vulnerabilitySome MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The pu…EPSS 0.65%6.9CVE-2026-93395Mongodb c driver vulnerabilityA missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-…EPSS 0.40%6.9CVE-2025-12119Mongodb c driver vulnerabilityA mongoc_bulk_operation_t may read invalid memory if large options are passed.EPSS 0.20%6.3CVE-2026-84963Mongodb c driver vulnerabilityAn incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be si…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2026-93394), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.