MongoDB EF Core Provider DFE via Conn Str
CVE-2026-92757 Published on September 17, 2026
Malformed connection string may disable field level encryption
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
Vulnerability Analysis
CVE-2026-92757 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Missing Encryption of Sensitive Data
The software does not encrypt sensitive or critical information before storage or transmission. The lack of proper data encryption passes up the guarantees of confidentiality, integrity, and accountability that properly implemented encryption conveys.
Products Associated with CVE-2026-92757
Want to know whenever a new CVE is published for MongoDB? stack.watch will email you.
Affected Versions
MongoDB Inc. MongoDB Entity Framework Core Provider:- Version 8.3.1 and below 8.4.4 is affected.
- Version 9.0.1 and below 9.1.4 is affected.
- Version 10.0.0 and below 10.0.4 is affected.