Inclusion of Sensitive Information in Log Files in MongoDB Server - CVE-2026-8200

 

Inclusion of Sensitive Information in Log Files in MongoDB Server - CVE-2026-8200

Published: August 18, 2026


Vulnerability identifier: #VU144154
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-8200
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log files in the schema validation log message handling when processing update or insert operations that violate a collection schema. A remote privileged user can submit data that triggers a schema validation failure to disclose sensitive information.

Only collections with schema validation enabled are affected.


Affected software

MongoDB Server

How to mitigate CVE-2026-8200

Install security update from vendor's website.

MongoDB Server - addressed in versions 7.0.34, 8.0.23, 8.2.9, 8.3.2

External References

Related Security Bulletins