Inclusion of Sensitive Information in Log Files in MongoDB Server - CVE-2026-9735

 

Inclusion of Sensitive Information in Log Files in MongoDB Server - CVE-2026-9735

Published: August 18, 2026


Vulnerability identifier: #VU144172
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9735
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log files in MongoDB Server logging during SASL authentication when connection health metric logging is enabled. A local user can trigger SASL authentication to disclose sensitive information.

The full authentication parameters may be written to the server log without redaction.


Affected software

MongoDB Server

How to mitigate CVE-2026-9735

Install security update from vendor's website.

MongoDB Server - update to 8.3.3

External References

Related Security Bulletins