Field Level Encryption Disabling in MongoDB Entity Framework Core Provider
CVE-2026-92757
6.8MEDIUM
Key Information:
- Vendor
MongoDB
- Vendor
- CVE Published:
- 17 September 2026
What is CVE-2026-92757?
Applications that utilize the MongoDB Entity Framework Core Provider and include a database name in their connection string may unintentionally disable field level encryption, which can lead to sensitive data exposure. This vulnerability emphasizes the need for secure coding practices and awareness among developers using this framework.
Affected Version(s)
MongoDB Entity Framework Core Provider 8.3.1 < 8.4.4
MongoDB Entity Framework Core Provider 9.0.1 < 9.1.4
MongoDB Entity Framework Core Provider 10.0.0 < 10.0.4