CVE-2026-92758 MEDIUM

CVE-2026-92758: Logs may collect sensitive information

Vendor Mongodb Inc.
Product MongoDB Entity Framework Core Provider
Weakness CWE-532 · Sensitive info in logs
Published September 17, 2026
Last update September 17, 2026

CVSS base score

5.7/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N

What the vulnerability does

01Description

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

Key dates

02Disclosure timeline

September 17, 2026 CVE published
September 17, 2026 Record updated

Related vulnerabilities

04Related CVE