Inclusion of Sensitive Information in Log Files in MongoDB Server - CVE-2026-9735
Published: August 18, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in MongoDB Server logging during SASL authentication when connection health metric logging is enabled. A local user can trigger SASL authentication to disclose sensitive information.
The full authentication parameters may be written to the server log without redaction.