CVE-2026-93763

A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.

  • Published Sep 18, 2026
  • CVSS 7.1 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-93763 at the National Vulnerability Database