SEPTEMBER 24, 2026
Live Feed
Back to database
Case File

CVE-2026-92758

MEDIUM · CVSS 5.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-09-24

CyberRota Analysis

AI-Generated

MongoDB is vulnerable when logging mode is set to DEBUG or when a malformed connection string is utilized, potentially exposing sensitive information like passwords and AWS secure access keys in application logs. This could lead to unauthorized access or data breaches if the logs are improperly secured. Organizations using MongoDB should prioritize addressing this vulnerability, particularly those handling sensitive data or operating in regulated environments.

CVE
CVE-2026-92758
Severity
MEDIUM
CVSS
5.5
EPSS
0.15%
MongoDB

Original NVD Description

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

Related CVEs

Other vulnerabilities affecting the same vendor(s)