Cleartext transmission of sensitive information in MongoDB Server - CVE-2026-9741
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to cleartext transmission of sensitive information in the query analysis processing of the $vectorSearch aggregation stage when handling filter expressions for encrypted fields. A remote user can submit a query containing literal values for encrypted fields to disclose sensitive information.
This affects Queryable Encryption (QE) and Client-Side Field Level Encryption (CSFLE).