← Back to CVE List
CVE-2026-92758NVD
Description
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.
CVSS Base Metrics
CVSS v3 (3.1)
MEDIUM 5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4 (4.0)
MEDIUM 5.7
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Weaknesses (CWE)
CWE-532 - CWE-532: Insertion of Sensitive Information into Log File
Affected & Patched Versions
| Product | Affected Versions | Patched Version |
|---|---|---|
| MongoDB Inc. MongoDB Entity Framework Core Provider | 8.0.0 - < 8.4.4, 9.0.0 - < 9.1.4, 10.0.0 - < 10.0.4 | N/A |