MongoDB Atlas KMS Escalation via Key Vault Write Access
CVE-2026-84962 Published on September 3, 2026

Authenticated KMS request forgery via CRLF injection in GCP key identifier strings
An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption.

NVD

Vulnerability Analysis

CVE-2026-84962 is exploitable with network access. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
HIGH
User Interaction:
PASSIVE

Weakness Type

What is a CRLF Injection Vulnerability?

The software uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

CVE-2026-84962 has been classified to as a CRLF Injection vulnerability or weakness.


Affected Versions

MongoDB libmongocrypt: