PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92757 MongoDB Inc. CVE debrief

CVE-2026-92757 debrief: MongoDB Entity Framework Core Provider vulnerability may disable field level encryption. This issue arises when a database name is included in the connection string, potentially leading to unintended security risks. Users should assess their exposure and verify field level encryption to mitigate potential threats. The vulnerability has a CVSS score of 6.8, indicating a medium severity level. MongoDB users, developers, and security teams should carefully evaluate the impact on their applications and take necessary precautions.

Vendor
MongoDB Inc.
Product
MongoDB Entity Framework Core Provider
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

MongoDB users, developers, and security teams should assess exposure and verify field level encryption. They should review their applications' usage of MongoDB Entity Framework Core Provider, check database connection strings for potential security risks, and ensure that field level encryption is enabled and functioning correctly. Additionally, they should consider the potential operational impacts, such as verifying

Why it matters

CVE-2026-92757 may disable field level encryption in MongoDB Entity Framework Core Provider; assess exposure and verify encryption

  • Verify field level encryption is enabled and functioning correctly
  • Assess potential security risks from database connection strings
  • Review MongoDB Entity Framework Core Provider usage in applications

Technical summary

Applications using MongoDB Entity Framework Core Provider may disable field level encryption when database name is in connection string. This occurs because the database name in the connection string may inadvertently override the field level encryption settings, leading to potential security risks. It is essential for users to review their database connection strings and verify that field level encryption is enabled and functioning correctly.

Defensive priority

Assess MongoDB Entity Framework Core Provider usage and verify field level encryption

Recommended defensive actions

  • Assess MongoDB Entity Framework Core Provider usage in applications
  • Verify field level encryption is enabled and functioning correctly
  • Review database connection strings for potential security risks

Evidence notes

Limited evidence from MongoDB and NVD; verify field level encryption impact. The CVE record was published on 2026-09-17T20:18:57.293Z and has not been modified since then. The official CVE Program record and NIST NVD vulnerability detail provide additional context. However, further verification is necessary to confirm the extent of the vulnerability and its potential effects on affected systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92757 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92757

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92757 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92757

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.