CVE-2026-92756 is a vulnerability in MongoDB
Published on September 17, 2026
Combining encryption settings may disable encryption
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.
Vulnerability Analysis
CVE-2026-92756 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Missing Encryption of Sensitive Data
The software does not encrypt sensitive or critical information before storage or transmission. The lack of proper data encryption passes up the guarantees of confidentiality, integrity, and accountability that properly implemented encryption conveys.
Products Associated with CVE-2026-92756
Want to know whenever a new CVE is published for MongoDB? stack.watch will email you.
Affected Versions
MongoDB Inc. MongoDB Entity Framework Core Provider:- Version 8.0.0 and below 8.4.3 is affected.
- Version 9.0.0 and below 9.1.3 is affected.
- Version 10.0.0 and below 10.0.3 is affected.