Executive brief
MongoDB Entity Framework Core Provider is a library that allows .NET applications to interact with MongoDB databases. When developers configure the library with a database name in the connection string (a documented and supported approach), the field-level encryption feature silently fails to activate, causing all supposedly encrypted sensitive data to be stored in plaintext in the database. This exposes customer data, payment card information, and other confidential records to database administrators, backup systems, and potential attackers.
Technical details
The vulnerability is a configuration validation failure in the connection string handling code. When a database name is provided in the MongoDB connection string URI, the GetOrCreateMongoClient method resolves the database name from the URI into an internal _databaseName variable, but passes the unmodified options object (with DatabaseName field still null) to the CreateSettings method. CreateSettings then constructs encryption field map keys as "null.collectionName" instead of "appdb.collectionName", causing the encryption schema to be applied to non-existent namespaces. Consequently, when actual CRUD operations target the real namespace (e.g., "appdb.People"), the encryption map fails to match and all declared-encrypted fields are silently stored and retrieved as plaintext. No error or warning is surfaced to the application. The root cause is the missing validation in MongoOptionsExtension.Validate and the disconnection between the resolved _databaseName and the CreateSettings invocation. Fix is available in versions 10.0.4, 9.1.4, and 8.4.4.
Affected products
- MongoDB Entity Framework Core Provider before 8.4.4, 9.x before 9.1.4, 10.x before 10.0.4
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Fixes available in versions 8.4.4, 9.1.4, and 10.0.4