6.8
CVE-2026-92756
- EPSS 0.05%
- Veröffentlicht 17.09.2026 19:04:51
- Zuletzt bearbeitet 24.09.2026 15:34:28
- Erkennungen
Combining encryption settings may disable encryption
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MongoDB ≫ Entity Framework Core Provider SwPlatform .net Version >= 8.0.0 < 8.4.3
MongoDB ≫ Entity Framework Core Provider SwPlatform .net Version >= 9.0.0 < 9.1.3
MongoDB ≫ Entity Framework Core Provider SwPlatform .net Version >= 10.0.0 < 10.0.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MongoDb | 6.8 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| MongoDb | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-311 Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
https://jira.mongodb.org/browse/EF-388