6.8

CVE-2026-92756

Combining encryption settings may disable encryption

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MongoDB ≫ Entity Framework Core Provider SwPlatform .net Version >= 8.0.0 < 8.4.3
MongoDB ≫ Entity Framework Core Provider SwPlatform .net Version >= 9.0.0 < 9.1.3
MongoDB ≫ Entity Framework Core Provider SwPlatform .net Version >= 10.0.0 < 10.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
MongoDb 6.8 0 0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
MongoDb 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-311 Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

https://jira.mongodb.org/browse/EF-388
Vendor Advisory
Permissions Required