Skip to content
MongoDBCVE-2026-93394

A flaw in libmongoc's SCRAM authentication implementation caused the client to...

Medium6.3CVE-2026-93394 · Published Sep 17, 2026 · updated Sep 25, 2026

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments.

MongoDB advisory

Affected versions

PackageAffectedFixed in
C Driver
Product
>= 2.0.0, < 2.3.22.3.2
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-303

More MongoDB advisories

All MongoDB
Advisory
MongoDB Mongoid: unsafe reflection
High8.3Sep 18
Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream
High8.1Sep 18
Insertion of Sensitive Information into Log File
Medium5.7Sep 17
Silent plaintext storage of encrypted fields via mis-keyed encryption map in the EF Core provider
Medium6.8Sep 17
MongoDB C Driver: integer overflow
Medium6.9Sep 17
MongoDB Entity Framework Core Provider: missing encryption
Medium6.8Sep 17

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.