Information Exposure in MongoDB Due to Improper Logging Configuration
CVE-2026-92758
5.7MEDIUM
Key Information:
- Vendor
MongoDB
- Vendor
- CVE Published:
- 17 September 2026
What is CVE-2026-92758?
This vulnerability arises when the logging mode is set to DEBUG or when a malformed MongoDB connection string is implemented. In such cases, application logs may inadvertently gather and expose sensitive information, including user passwords and AWS secure access keys, risking unauthorized access to critical resources. It's crucial for users to verify their logging configurations and implement stringent measures to safeguard their sensitive data.
Affected Version(s)
MongoDB Entity Framework Core Provider 8.0.0 < 8.4.4
MongoDB Entity Framework Core Provider 9.0.0 < 9.1.4
MongoDB Entity Framework Core Provider 10.0.0 < 10.0.4