Inclusion of Sensitive Information in Log Files in MongoDB Server - CVE-2026-9751
Published: August 18, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in the ldapQueryPassword runtime setParameter handling when setting the ldapQueryPassword parameter through the runtime setParameter command. A local user can set the ldapQueryPassword parameter to cause the password to be written to mongod.log in plain text to disclose sensitive information.