CVE-2026-93764: CWE-312: Cleartext Storage of Sensitive Information in MongoDB Inc. Mongoid
Mongoid versions 9.0.0 through 9.0.11 and 9.1.0 may fail to apply encryption rules on embedded model fields when generating client-side field-level encryption schemas. This can cause sensitive data intended for encryption to be stored in cleartext without any warning or error, exposing it to anyone with read access to the database or backups.
AI Analysis
Technical Summary
CVE-2026-93764 describes a vulnerability in MongoDB Inc.'s Mongoid where encryption rules for fields declared on embedded models may be omitted during the generation of client-side field-level encryption schemas. As a result, applications enabling this feature might store sensitive values in readable form rather than encrypted. This flaw does not produce errors or warnings, potentially allowing unauthorized parties with routine read access to the database, backups, or data files to view data meant to remain confidential.
Potential Impact
Sensitive information intended to be encrypted may be stored in cleartext, exposing it to unauthorized readers with access to the database or its backups. This compromises data confidentiality but does not indicate privilege escalation or integrity impact. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should carefully review encryption schema configurations for embedded models and consider additional protective controls on database access and backups.
CVE-2026-93764: CWE-312: Cleartext Storage of Sensitive Information in MongoDB Inc. Mongoid
Description
Mongoid versions 9.0.0 through 9.0.11 and 9.1.0 may fail to apply encryption rules on embedded model fields when generating client-side field-level encryption schemas. This can cause sensitive data intended for encryption to be stored in cleartext without any warning or error, exposing it to anyone with read access to the database or backups.
CVSS v4.0
Score 7.1high
Affected software
MongoDB Inc.
Mongoid
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93764 describes a vulnerability in MongoDB Inc.'s Mongoid where encryption rules for fields declared on embedded models may be omitted during the generation of client-side field-level encryption schemas. As a result, applications enabling this feature might store sensitive values in readable form rather than encrypted. This flaw does not produce errors or warnings, potentially allowing unauthorized parties with routine read access to the database, backups, or data files to view data meant to remain confidential.
Potential Impact
Sensitive information intended to be encrypted may be stored in cleartext, exposing it to unauthorized readers with access to the database or its backups. This compromises data confidentiality but does not indicate privilege escalation or integrity impact. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should carefully review encryption schema configurations for embedded models and consider additional protective controls on database access and backups.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mongodb
- Date Reserved
- 2026-09-18T16:51:42.828Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aad75a155bf5e2cf54f361b
Added to database: 09/18/2026, 17:32:17 UTC
Last enriched: 09/18/2026, 17:46:27 UTC
Last updated: 09/18/2026, 19:27:19 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.