CVE-2026-92756

Summary

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.

Affected Software

VendorProductVersion RangeStatus
MongoDB Inc.MongoDB Entity Framework Core Provider8.0.0 < 8.4.3affected
MongoDB Inc.MongoDB Entity Framework Core Provider9.0.0 < 9.1.3affected
MongoDB Inc.MongoDB Entity Framework Core Provider10.0.0 < 10.0.3affected

Weaknesses

  • CWE-311: CWE-311: Missing Encryption of Sensitive Data

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References