{"id":"CVE-2026-92756","title":"Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…","summary":"Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-311"],"vendor":"MongoDB Inc.","product":"MongoDB Entity Framework Core Provider","affected":["mongodb_entity_framework_core_provider >= 8.0.0 < 8.4.3","mongodb_entity_framework_core_provider >= 9.0.0 < 9.1.3","mongodb_entity_framework_core_provider >= 10.0.0 < 10.0.3"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:05:01.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92756","references":[{"url":"https://jira.mongodb.org/browse/EF-388","label":"cna@mongodb.com"}],"tags":["nvd","cve.org"],"epss":0.00053,"epssPercentile":0.00002,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T20:02:09.501080Z"},"ingestedAt":"2026-09-17T19:26:25.327Z","slug":"CVE-2026-92756","body":"## Overview\n\nApplications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}