Description
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.
Published: 2026-09-17
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure via logs
Action: Restrict Logging
AI Analysis

Impact

In the MongoDB Entity Framework Core Provider, enabling DEBUG logging or using a malformed MongoDB connection string causes application logs to capture sensitive data such as passwords and AWS secure access keys. When this logging mode is active, the provider does not filter or redact credentials before writing them to the log stream, resulting in accidental disclosure of confidential information.

Affected Systems

The vulnerability impacts MongoDB Inc.’s MongoDB Entity Framework Core Provider. No specific version range is provided in the advisory, so all versions of this provider may be affected until a patch is released.

Risk and Exploitability

The CVSS score of 5.7 indicates a medium severity threat. The EPSS score is less than 1%, suggesting the likelihood of exploitation is relatively low, and the vulnerability is not listed in CISA’s KEV catalog. Attackers who can trigger DEBUG logging or supply a malformed connection string—such as developers, automated build systems, or privileged application components—can cause sensitive data to be written to logs that may be accessed by third parties or retained for extended periods. Once revealed, the information may be leveraged for credential theft or further compromise of the target environment.

Generated by OpenCVE AI on September 19, 2026 at 06:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Set the logging level to WARN or INFO to disable DEBUG output for the MongoDB Provider
  • Validate and correct all MongoDB connection strings to remove malformed inputs that could enable unintended logging
  • Configure log storage to be secure and apply redaction or encryption policies so that credentials are not exposed in plaintext
  • Apply any vendor-released patch for the Entity Framework Core Provider when it becomes available

Generated by OpenCVE AI on September 19, 2026 at 06:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 24 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb entity Framework Core Provider
CPEs cpe:2.3:a:mongodb:entity_framework_core_provider:*:*:*:*:*:.net:*:*
Vendors & Products Mongodb entity Framework Core Provider

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Entity Framework Core Provider
Vendors & Products Mongodb
Mongodb mongodb Entity Framework Core Provider

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.
Title Logs may collect sensitive information
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Mongodb Entity Framework Core Provider Mongodb Entity Framework Core Provider
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-17T19:53:43.819Z

Reserved: 2026-09-16T18:58:37.344Z

Link: CVE-2026-92758

cve-icon Vulnrichment

Updated: 2026-09-17T19:53:39.218Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T20:18:57.433

Modified: 2026-09-24T15:34:25.450

Link: CVE-2026-92758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T06:15:17Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File