CVE-2026-93393: CWE-787: Out-of-bounds Write in MongoDB Inc. C Driver
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to, or an attacker able to impersonate or redirect the client's connection, can cause the driver to write attacker-supplied data outside the bounds of a heap allocation while processing incoming encrypted traffic. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Successful exploitation may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-93393) affects the MongoDB C Driver's TLS transport layer on Windows platforms. A heap-based buffer overflow occurs when processing incoming encrypted traffic, allowing an attacker controlling or impersonating the remote endpoint to write outside the bounds of a heap allocation. This happens before any application-level authentication, making it exploitable without user interaction or credentials. The impact includes potential memory corruption, information disclosure of adjacent heap memory, or crashing the client process. The affected versions span multiple release lines from 1.24.0 through 2.4.0 as explicitly listed.
Potential Impact
Successful exploitation can cause memory corruption in the client process, potentially leading to disclosure of adjacent heap memory or termination of the process. Because the vulnerability occurs before authentication, it can be triggered by any remote endpoint the client connects to or an attacker capable of redirecting or impersonating that endpoint. This elevates the risk of exploitation in network environments where attackers can intercept or spoof connections.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Users should monitor MongoDB Inc. advisories for updates. Until a patch is available, avoid connecting the affected MongoDB C Driver versions to untrusted or potentially compromised endpoints, especially over networks where man-in-the-middle attacks are possible.
CVE-2026-93393: CWE-787: Out-of-bounds Write in MongoDB Inc. C Driver
Description
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to, or an attacker able to impersonate or redirect the client's connection, can cause the driver to write attacker-supplied data outside the bounds of a heap allocation while processing incoming encrypted traffic. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Successful exploitation may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
CVSS v4.0
Score 9.2critical
Affected software
MongoDB Inc.
C Driver
pkg:github/mongodb/mongo-c-driverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-93393) affects the MongoDB C Driver's TLS transport layer on Windows platforms. A heap-based buffer overflow occurs when processing incoming encrypted traffic, allowing an attacker controlling or impersonating the remote endpoint to write outside the bounds of a heap allocation. This happens before any application-level authentication, making it exploitable without user interaction or credentials. The impact includes potential memory corruption, information disclosure of adjacent heap memory, or crashing the client process. The affected versions span multiple release lines from 1.24.0 through 2.4.0 as explicitly listed.
Potential Impact
Successful exploitation can cause memory corruption in the client process, potentially leading to disclosure of adjacent heap memory or termination of the process. Because the vulnerability occurs before authentication, it can be triggered by any remote endpoint the client connects to or an attacker capable of redirecting or impersonating that endpoint. This elevates the risk of exploitation in network environments where attackers can intercept or spoof connections.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Users should monitor MongoDB Inc. advisories for updates. Until a patch is available, avoid connecting the affected MongoDB C Driver versions to untrusted or potentially compromised endpoints, especially over networks where man-in-the-middle attacks are possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mongodb
- Date Reserved
- 2026-09-17T20:10:59.785Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aac51e955bf5e2cf5e0db78
Added to database: 09/17/2026, 20:47:37 UTC
Last enriched: 09/17/2026, 21:32:24 UTC
Last updated: 09/18/2026, 04:01:24 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.