Information Exposure in MongoDB Due to Improper Logging Configuration
CVE-2026-92758

5.7MEDIUM

Key Information:

Vendor

MongoDB

Vendor
CVE Published:
17 September 2026

What is CVE-2026-92758?

This vulnerability arises when the logging mode is set to DEBUG or when a malformed MongoDB connection string is implemented. In such cases, application logs may inadvertently gather and expose sensitive information, including user passwords and AWS secure access keys, risking unauthorized access to critical resources. It's crucial for users to verify their logging configurations and implement stringent measures to safeguard their sensitive data.

Affected Version(s)

MongoDB Entity Framework Core Provider 8.0.0 < 8.4.4

MongoDB Entity Framework Core Provider 9.0.0 < 9.1.4

MongoDB Entity Framework Core Provider 10.0.0 < 10.0.4

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.