CVE-2026-92757: Malformed connection string may disable field level encryption
Published Sep 17, 2026
·Updated
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
Affected Software
1 affected component
MongoDB Entity Framework Core Provider
Event History
Sep 17, 2026
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which applications are exposed to this issue?
Applications built on the MongoDB Entity Framework Core Provider are exposed if they place a database name in the connection string and rely on field level encryption.
2
What access does an attacker need to exploit this?
The vulnerability is rated as requiring local access and low privileges. No user interaction is required.
3
What is the security impact if exploitation succeeds?
Field level encryption may be disabled, resulting in high confidentiality impact. The provided assessment indicates no integrity or availability impact.