CVE-2026-9741
EUVD-2026-3585909.06.2026, 23:17
A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of ciphertext.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.3 | CNA |
| mongodb | mongodb | 8.2.0 ≤ 𝑥 < 8.2.10 | CNA |
| mongodb | mongodb | 8.0.0 ≤ 𝑥 < 8.0.24 | CNA |
| mongodb | mongodb | 7.0.0 ≤ 𝑥 < 7.0.35 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure