Data exposure vulnerability in MongoDB Entity Framework Core Provider
CVE-2026-92756

6.8MEDIUM

Key Information:

Vendor

MongoDB

Vendor
CVE Published:
17 September 2026

What is CVE-2026-92756?

The MongoDB Entity Framework Core Provider contains a vulnerability that can result in sensitive information being stored unencrypted. This issue arises when independent encryption settings are used in conjunction with the provider's own settings, leading to the unintended consequences of losing TLS and schema-map configurations. As a consequence, fields that are meant to be protected may be compromised and saved without encryption in the database, potentially exposing confidential data to unauthorized access.

Affected Version(s)

MongoDB Entity Framework Core Provider 8.0.0 < 8.4.3

MongoDB Entity Framework Core Provider 9.0.0 < 9.1.3

MongoDB Entity Framework Core Provider 10.0.0 < 10.0.3

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.