PT-2026-48298 · Mongodb · Mongodb

CVE-2026-9735

·

Published

2026-06-09

·

Updated

2026-06-16

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MongoDB server (affected versions not specified)
Description The server may log authentication parameters, including credentials, to the server log during SASL (Simple Authentication and Security Layer) authentication. This occurs when connection health metric logging is enabled, causing the full authentication parameters to be written to the log without redaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MONGODB-2026-9735
CVE-2026-9735

Affected Products

Mongodb