← Vulnerability feed

Vulnerability record · CVE-2026-93763 · published 18 September 2026

CVE-2026-93763: Mongodb mongoid cleartext storage of sensitive data vulnerability

Mongodb · Mongoid

A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.

7.1 CVSS 4.0 High EPSS 0.15% · top 96.3% CWE-312 · Cleartext storage of sensitive data
7.1CVSS 4.0 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
24 Sep 2026Last modified by NVD

Description

A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jira.mongodb.org/browse/MONGOID-5984 Permissions Required

Track CVE-2026-93763 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2026-93762Mongodb mongoid vulnerabilityMongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field…EPSS 0.57%8.8CVE-2026-93759Mongodb mongoid code injection vulnerabilityMongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side Java…EPSS 0.40%8.7CVE-2026-93761Mongodb mongoid inefficient regular expression (redos) vulnerabilityAn inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated pa…EPSS 0.46%8.6CVE-2026-93758Mongodb mongoid insecure direct object reference vulnerabilityAn insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application p…EPSS 0.36%8.3CVE-2026-93760Mongodb mongoid vulnerabilityMongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building m…EPSS 0.47%8.3CVE-2026-93765Mongodb mongoid vulnerabilityMongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed thr…EPSS 0.51%7.1CVE-2026-93764Mongodb mongoid cleartext storage of sensitive data vulnerabilityMongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications …EPSS 0.15%5.7CVE-2011-4723D-Link DIR-300 router stores passwords in cleartextThe D-Link DIR-300 router stores passwords in cleartext rather than in a protected form. Anyone who can reach the stored data can read credentials di…KEVEPSS 3.1%analysed

Source: NIST National Vulnerability Database (record CVE-2026-93763), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.