CVE-2026-92757

Summary

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

Affected Software

VendorProductVersion RangeStatus
MongoDB Inc.MongoDB Entity Framework Core Provider8.3.1 < 8.4.4affected
MongoDB Inc.MongoDB Entity Framework Core Provider9.0.1 < 9.1.4affected
MongoDB Inc.MongoDB Entity Framework Core Provider10.0.0 < 10.0.4affected

Weaknesses

  • CWE-311: CWE-311: Missing Encryption of Sensitive Data

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References