CVE-2026-92757: MongoDB Entity Framework Core Provider

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

Affected products

  • MongoDB Entity Framework Core Provider: from 8.0.0, before 8.4.4 (fixed in 8.4.4); from 9.0.0, before 9.1.4 (fixed in 9.1.4); from 10.0.0, before 10.0.4 (fixed in 10.0.4)

Published 2026-09-17. Last modified 2026-09-24.