Inclusion of Sensitive Information in Log Files in MongoDB Server - CVE-2026-8200
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in the schema validation log message handling when processing update or insert operations that violate a collection schema. A remote privileged user can submit data that triggers a schema validation failure to disclose sensitive information.
Only collections with schema validation enabled are affected.