CVE-2026-93394
libmongoc SCRAM client nonce-validation bypass
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments.
| CWE | CWE-303 |
| Vendor | mongodb inc. |
| Product | c driver |
| Published | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for mongodb inc. c driver
Be the first to know when new low vulnerabilities affecting mongodb inc. c driver are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
MongoDB Inc. / C Driver
2.0.0 < 2.3.2