Inclusion of Sensitive Information in Log Files in MongoDB Server - CVE-2026-9751

 

Inclusion of Sensitive Information in Log Files in MongoDB Server - CVE-2026-9751

Published: August 18, 2026


Vulnerability identifier: #VU144169
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9751
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log files in the ldapQueryPassword runtime setParameter handling when setting the ldapQueryPassword parameter through the runtime setParameter command. A local user can set the ldapQueryPassword parameter to cause the password to be written to mongod.log in plain text to disclose sensitive information.


Affected software

MongoDB Server

How to mitigate CVE-2026-9751

Install security update from vendor's website.

MongoDB Server - addressed in versions 7.0.35, 8.0.24, 8.2.10, 8.3.3

External References

Related Security Bulletins