SEPTEMBER 24, 2026
Live Feed
Back to database
Case File

CVE-2026-93763

MEDIUM · CVSS 6.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-09-24

CyberRota Analysis

AI-Generated

A vulnerability exists in the object-document mapper's encryption configuration, allowing fields designated for client-side field-level encryption to be stored in cleartext without any error notifications. As a result, users with standard read access to the database can inadvertently access sensitive information that should have been encrypted. Organizations utilizing this object-document mapper should prioritize addressing this issue to prevent potential data breaches and protect sensitive data.

CVE
CVE-2026-93763
Severity
MEDIUM
CVSS
6.5
EPSS
0.15%

Original NVD Description

A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.

Related CVEs

Other vulnerabilities affecting the same vendor(s)