Executive brief
MongoDB's Entity Framework Core provider for .NET inadvertently logs sensitive credentials and tokens to application logs when connection strings contain secrets outside the password field—such as AWS session tokens or proxy passwords. An attacker with access to application logs can harvest these credentials to authenticate to the database, cloud services, or proxy infrastructure without needing to exploit the application itself.
Technical details
The vulnerability is a credential exposure (CWE-532: Insertion of Sensitive Information into Log Files) in the MongoOptionsExtension.SanitizeConnectionStringForLogging() method. The sanitizer redacts only the password field from connection strings but fails to redact other secrets embedded in query-string options (e.g., authMechanismProperties, proxyPassword) or the username; these unredacted values are serialized into the provider-options log fragment that Entity Framework Core writes at Information level by default during context initialization. Additionally, if the connection string is malformed, an exception is thrown before redaction occurs, leaking the raw unredacted string in exception logs. Attack vectors include: (1) reading application logs directly if the attacker has file/log aggregation access, (2) intercepting logs in downstream pipelines. No user interaction or attacker-supplied input is required—the application's own connection string configuration triggers the leak automatically. Patches are available in versions 10.0.4, 9.1.4, and 8.4.4.
Affected products
- MongoDB Entity Framework Core Provider before 8.4.4, 9.x before 9.1.4, 10.x before 10.0.4
Timeline
- 2026-09-17: disclosed: CVE-2026-92758 published
- 2026-09-17: patched: Fixed in versions 8.4.4, 9.1.4, 10.0.4