CVE-2026-92758

Summary

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

Affected Software

VendorProductVersion RangeStatus
MongoDB Inc.MongoDB Entity Framework Core Provider8.0.0 < 8.4.4affected
MongoDB Inc.MongoDB Entity Framework Core Provider9.0.0 < 9.1.4affected
MongoDB Inc.MongoDB Entity Framework Core Provider10.0.0 < 10.0.4affected

Weaknesses

  • CWE-532: CWE-532: Insertion of Sensitive Information into Log File

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References