{"id":"CVE-2026-93394","summary":"libmongoc SCRAM client nonce-validation bypass","details":"A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments.","modified":"2026-09-27T03:47:38.709315847Z","published":"2026-09-17T20:31:27.875Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.3.2"}]}],"cna_assigner":"mongodb","cwe_ids":["CWE-303"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93394.json"},"references":[{"type":"WEB","url":"https://jira.mongodb.org/browse/CDRIVER-6315"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93394.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93394"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb/mongo-c-driver","events":[{"introduced":"67817df0a9ed11b07e457477e6db1384da9421c4"},{"fixed":"76e9b7d7a2363f765a125e8015e48c7b3ff4899e"}],"database_specific":{"cpe":"cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*","extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.3.2"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93394.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}