MongoDB Atlas KMS Escalation via Key Vault Write Access
CVE-2026-84962 Published on September 3, 2026
Authenticated KMS request forgery via CRLF injection in GCP key identifier strings
An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption.
Vulnerability Analysis
CVE-2026-84962 is exploitable with network access. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is a CRLF Injection Vulnerability?
The software uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.
CVE-2026-84962 has been classified to as a CRLF Injection vulnerability or weakness.
Affected Versions
MongoDB libmongocrypt:- Before 1.20.2 is affected.