CVE-2026-92758

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

  • Published Sep 17, 2026
  • CVSS 5.7 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-92758 at the National Vulnerability Database