{"id":"CVE-2026-93763","title":"A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any erro…","summary":"A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any erro…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-312"],"vendor":"MongoDB Inc.","product":"Mongoid","affected":["Mongoid 9.1.0","Mongoid >= 9.0.0 <= 9.0.11"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T19:17:18.010","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93763","references":[{"url":"https://jira.mongodb.org/browse/MONGOID-5984","label":"cna@mongodb.com"}],"tags":["nvd","cve.org"],"epss":0.001,"epssPercentile":0.00996,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-21T18:14:33.714412Z"},"ingestedAt":"2026-09-18T17:46:41.551Z","slug":"CVE-2026-93763","body":"## Overview\n\nA protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}