CVE-2026-106434 | MongoDB libmongocrypt up to 1.20.4 Explicit Decryption missing encryption

SecurityVulns

A vulnerability described as problematic has been identified in MongoDB libmongocrypt up to 1.20.4. Affected is an unknown function of the component Explicit Decryption Component. Executing a manipulation can lead to missing encryption of sensitive data.

This vulnerability is handled as CVE-2026-106434. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More