{"id":"CVE-2026-106433","title":"Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields","summary":"Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key va…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-843"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T20:49:23.240","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106433","references":[{"url":"https://jira.mongodb.org/browse/MONGOCRYPT-964","label":"cna@mongodb.com"}],"tags":["nvd"],"ingestedAt":"2026-10-08T20:06:22.182Z","slug":"CVE-2026-106433","body":"## Overview\n\nImproper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault documents, or a server that returns such a key document, can cause invalid memory access and invalid frees in the client process. This can terminate the application or corrupt process memory.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}