PT-2026-71304 · Mongodb · Mongodb Sql Schema Builder Cli

CVE-2026-19502

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MongoDB SQL Schema Builder CLI (affected versions not specified)
Description The application records its startup configuration to standard output and, if file logging is enabled, to a log file on disk. Certain connection settings are written without redaction, allowing authentication material provided by the operator to appear in plaintext within the diagnostic output. A local user with read access to the terminal session or the log directory, or any entity with access to the log collection location, could obtain these sensitive values.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19502

Affected Products

Mongodb Sql Schema Builder Cli