216.73.217.80

CVE-2026-9741

· Published 09/06/2026 23:17 · Modified 10/06/2026 19:43

Labels: CVE-2026-9741 2026-06-09CVE-2026-9741CWE-319[email protected]

Essential information

Published
09/06/2026 23:17
Modified
10/06/2026 19:43
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of ciphertext.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mongodb / mongodb cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

References