PatchSiren cyber security CVE debrief
CVE-2026-92757 MongoDB Inc. CVE debrief
CVE-2026-92757 debrief: MongoDB Entity Framework Core Provider vulnerability may disable field level encryption. This issue arises when a database name is included in the connection string, potentially leading to unintended security risks. Users should assess their exposure and verify field level encryption to mitigate potential threats. The vulnerability has a CVSS score of 6.8, indicating a medium severity level. MongoDB users, developers, and security teams should carefully evaluate the impact on their applications and take necessary precautions.
- Vendor
- MongoDB Inc.
- Product
- MongoDB Entity Framework Core Provider
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
MongoDB users, developers, and security teams should assess exposure and verify field level encryption. They should review their applications' usage of MongoDB Entity Framework Core Provider, check database connection strings for potential security risks, and ensure that field level encryption is enabled and functioning correctly. Additionally, they should consider the potential operational impacts, such as verifying
Why it matters
CVE-2026-92757 may disable field level encryption in MongoDB Entity Framework Core Provider; assess exposure and verify encryption
- Verify field level encryption is enabled and functioning correctly
- Assess potential security risks from database connection strings
- Review MongoDB Entity Framework Core Provider usage in applications
Technical summary
Applications using MongoDB Entity Framework Core Provider may disable field level encryption when database name is in connection string. This occurs because the database name in the connection string may inadvertently override the field level encryption settings, leading to potential security risks. It is essential for users to review their database connection strings and verify that field level encryption is enabled and functioning correctly.
Defensive priority
Assess MongoDB Entity Framework Core Provider usage and verify field level encryption
Recommended defensive actions
- Assess MongoDB Entity Framework Core Provider usage in applications
- Verify field level encryption is enabled and functioning correctly
- Review database connection strings for potential security risks
Evidence notes
Limited evidence from MongoDB and NVD; verify field level encryption impact. The CVE record was published on 2026-09-17T20:18:57.293Z and has not been modified since then. The official CVE Program record and NIST NVD vulnerability detail provide additional context. However, further verification is necessary to confirm the extent of the vulnerability and its potential effects on affected systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92757 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92757
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92757 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92757
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://jira.mongodb.org/browse/EF-389
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.