CVE-2026-92757: MongoDB Entity Framework Core Provider
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
Affected products
- MongoDB Entity Framework Core Provider: from 8.0.0, before 8.4.4 (fixed in 8.4.4); from 9.0.0, before 9.1.4 (fixed in 9.1.4); from 10.0.0, before 10.0.4 (fixed in 10.0.4)
Published 2026-09-17. Last modified 2026-09-24.