CVE-2026-92757Medium· 5.5▾ SunlitApplications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.05%
Last analysed / modified upstream
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
entity_framework_core_provider >= 8.0.0, < 8.4.4entity_framework_core_provider >= 9.0.0, < 9.1.4entity_framework_core_provider >= 10.0.0, < 10.0.4Upgrade past the affected range:
entity_framework_core_provider 10.0.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92756Medium· 5.5Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…
CVE-2026-92758Medium· 5.5If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.
CVE-2026-96747Medium· 5.0The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host
CVE-2026-96749High· 8.4An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data
CVE-2026-96748Medium· 6.5PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters
CVE-2026-96750High· 7.1MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view