Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/MONGOCRYPT-960 |
|
Thu, 03 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb libmongocrypt |
|
| Vendors & Products |
Mongodb
Mongodb libmongocrypt |
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption. | |
| Title | Authenticated KMS request forgery via CRLF injection in GCP key identifier strings | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-03T15:34:35.133Z
Reserved: 2026-09-02T17:58:52.742Z
Link: CVE-2026-84962
No data.
Status : Awaiting Analysis
Published: 2026-09-03T16:18:24.967
Modified: 2026-09-03T16:25:43.557
Link: CVE-2026-84962
No data.
OpenCVE Enrichment
Updated: 2026-09-03T16:30:05Z
-
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')