CVE-2026-106433
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Oct 08, 2026
Vendor
unknown
Description
Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault documents, or a server that returns such a key document, can cause invalid memory access and invalid frees in the client process. This can terminate the application or corrupt process memory.