CVE-2026-9741
EUVD-2026-3585909.06.2026, 23:17
A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of ciphertext.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mongodb | mongodb | 7.0.0 ≤ 𝑥 < 7.0.35 |
| mongodb | mongodb | 8.0.0 ≤ 𝑥 < 8.0.24 |
| mongodb | mongodb | 8.2.0 ≤ 𝑥 < 8.2.10 |
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration