SEPTEMBER 24, 2026
Live Feed
Back to database
Case File

CVE-2026-93764

MEDIUM · CVSS 6.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-09-24

CyberRota Analysis

AI-Generated

Mongoid is vulnerable due to its failure to apply encryption rules for fields in embedded models when creating client-side field-level encryption schemas. This oversight allows sensitive data to be stored in plaintext, potentially exposing it to unauthorized users with read access to the database or backups. Organizations using Mongoid with enabled encryption features should prioritize addressing this vulnerability to protect sensitive information from unauthorized disclosure.

CVE
CVE-2026-93764
Severity
MEDIUM
CVSS
6.5
EPSS
0.15%

Original NVD Description

Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with no error or warning. A party with routine read access to the database, a backup, or the underlying data files may then see data that was meant to remain unreadable outside the application.

Related CVEs

Other vulnerabilities affecting the same vendor(s)