Description
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
Published: 2026-09-17
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality loss due to disabled field level encryption
Action: Apply Patch
AI Analysis

Impact

The defect in the MongoDB Entity Framework Core Provider allows a malformed connection string that includes a database name to unintentionally turn off field level encryption. As a result, data stored and retrieved through that provider may be persisted in plain form, exposing sensitive information to anyone with access to the database. The weakness is an improper handling of sensitive information (CWE-311).

Affected Systems

Applications that rely on MongoDB Inc.'s Entity Framework Core Provider and embed a database name in their connection string are affected. No specific version range is listed, so any edition of the provider that includes the vulnerability is at risk.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not in the CISA Known Exploited Vulnerabilities catalog, reducing the likelihood of public exploitation. The most plausible attack vector is misconfiguration or tampering with the connection string by insiders or compromised application code, which can lead to unencrypted data storage without any additional privileges.

Generated by OpenCVE AI on September 19, 2026 at 06:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest version of the MongoDB Entity Framework Core Provider that resolves the connection string handling issue.
  • Review and validate all connection strings in the application to ensure that database names are correctly specified and encryption flags are enabled.
  • Conduct a post‑deployment audit of the database to confirm that field level encryption remains active across all collections.

Generated by OpenCVE AI on September 19, 2026 at 06:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 24 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb entity Framework Core Provider
CPEs cpe:2.3:a:mongodb:entity_framework_core_provider:*:*:*:*:*:.net:*:*
Vendors & Products Mongodb entity Framework Core Provider

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Entity Framework Core Provider
Vendors & Products Mongodb
Mongodb mongodb Entity Framework Core Provider

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
Title Malformed connection string may disable field level encryption
Weaknesses CWE-311
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Mongodb Entity Framework Core Provider Mongodb Entity Framework Core Provider
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-17T19:50:41.068Z

Reserved: 2026-09-16T18:58:33.464Z

Link: CVE-2026-92757

cve-icon Vulnrichment

Updated: 2026-09-17T19:49:08.313Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T20:18:57.293

Modified: 2026-09-24T15:34:22.627

Link: CVE-2026-92757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T06:45:17Z

Weaknesses
  • CWE-311

    Missing Encryption of Sensitive Data