CVE-2026-106434 | MongoDB libmongocrypt up to 1.20.4 Explicit Decryption missing encryption
A vulnerability described as problematic has been identified in MongoDB libmongocrypt up to 1.20.4. Affected is an unknown function of the component Explicit Decryption Component. Executing a manipulation can lead to missing encryption of sensitive data.
This vulnerability is handled as CVE-2026-106434. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More