Threats Tagged 'cve-2026-93394'
View all threats tagged with 'cve-2026-93394'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-93394'
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in libmongoc's SCRAM authentication allows a client to proceed with authentication and send client proof despite a nonce mismatch in the server's initial message. This flaw could enable a man-in-the-middle attacker to inject a malicious server-first-message with controlled parameters, capturing client proof for offline password cracking. The issue is mitigated by the use of TLS, which is standard in production environments. Join the discussion | GCVE Database | 09/17/2026, 21:31:44 UTC Added: 09/18/2026, 01:03:27 UTC |
0 A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments. Join the discussion | CVE Database V5 | 09/17/2026, 20:31:27 UTC Added: 09/17/2026, 20:47:37 UTC |
Showing 1 to 2 of 2 results