CVE-2026-92758: MongoDB Entity Framework Core Provider

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

Affected products

  • MongoDB Entity Framework Core Provider: from 8.0.0, before 8.4.4 (fixed in 8.4.4); from 9.0.0, before 9.1.4 (fixed in 9.1.4); from 10.0.0, before 10.0.4 (fixed in 10.0.4)

Published 2026-09-17. Last modified 2026-09-24.