← Back to CVE search

CVE-2026-9735

MongoDB

Description

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

CVSS 5.5EPSS 0.11900000000000001%Risk 0.56
View source
Published
2026-06-09 23:17:03
Affected versions
unknown
Type
Critical software
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N